SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 67660: The text object in SAS® Visual Analytics contains a cross-site scripting (XSS) vulnerability

DetailsHotfixAboutRate It

Severity: Medium

Description: The text object in SAS Visual Analytics contains a cross-site scripting (XSS) vulnerability that enables JavaScript to be embedded in a certain property. 

Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual Analytics (on SAS Viya)Cloud Foundry8.52020.1.5ViyaViya
Linux for x648.52020.1.5ViyaViya
Microsoft® Windows® for x648.52020.1.5ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.