Problem Note 67540: SAS® Visual Data Builder allows unauthorized users to execute arbitrary SAS® code
Severity: Critical
Description: SAS Visual Data Builder contains an authorization bypass vulnerability.
Potential Impact: Authenticated users, without the proper roles to use the SAS Visual Data Builder application, can execute arbitrary SAS code.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS Visual Analytics | Microsoft® Windows® for x64 | 7.5 | | 9.4 TS1M6 | |
Linux for x64 | 7.5 | | 9.4 TS1M6 | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Users without proper roles in the metadata can submit SAS code to applications, and it will be executed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2021-04-09 16:22:39 |
Date Created: | 2021-03-03 06:54:10 |