SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 67728: Scalable Vector Graphic (SVG) images in SAS® Customer Intelligence Studio are affected by a security vulnerability

DetailsHotfixAboutRate It

Severity: Medium

Description: In SAS Customer Intelligence Studio, you can use a link to an external Scalable Vector Graphics (SVG) image. The external SVG image can contain malicious JavaScript code.

Potential Impact: Users might execute the malicious JavaScript code unknowingly.

Click the Hot Fix tab in this note to access the hot fix for this issue.

After you apply the hot fix, a new property named sas.ci.turnImageAttachmentsOff will be available. The new property can be added to the index.jsp file that resides in the SAS-configuration-directory\Lev1\Web\WebAppServer\SASServer6_1\sas_webapps\sas.customerintelligencestudio.war directory, as follows.

<sas-html:config-property name="sas.servicePlatform" value="WIP"/>
<sas-html:config-property name="sas.ci" value="{}" quote="false"/>
<sas-html:config-property name="sas.ci.turnAttachmentsOff" value="true"/>
<sas-html:config-property name="sas.ci.turnImageAttachmentsOff" value="true"/>
<sas-html:config-property name="sas.applicationSwitcher" value="{}" quote="false"/>
<sas-html:config-property name="sas.applicationSwitcher.hubServiceAvailable" value="<%= hubServiceAvailable %>" quote="false"/>

When you change the value to true, the Image section for both campaigns and treatments is hidden completely. 

 



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Customer Intelligence StudioMicrosoft® Windows® for x646.6
Microsoft Windows 8 Enterprise 32-bit6.6
Microsoft Windows 8 Enterprise x646.6
Microsoft Windows 8 Pro 32-bit6.6
Microsoft Windows 8 Pro x646.6
Microsoft Windows 8.1 Enterprise 32-bit6.6
Microsoft Windows 8.1 Enterprise x646.6
Microsoft Windows 8.1 Pro 32-bit6.6
Microsoft Windows 8.1 Pro x646.6
Microsoft Windows 106.6
Microsoft Windows 95/986.6
Microsoft Windows 2000 Advanced Server6.6
Microsoft Windows 2000 Datacenter Server6.6
Microsoft Windows 2000 Server6.6
Microsoft Windows 2000 Professional6.6
Microsoft Windows NT Workstation6.6
Microsoft Windows Server 2003 Datacenter Edition6.6
Microsoft Windows Server 2003 Enterprise Edition6.6
Microsoft Windows Server 2003 Standard Edition6.6
Microsoft Windows Server 2003 for x646.6
Microsoft Windows Server 20086.6
Microsoft Windows Server 2008 R26.6
Microsoft Windows Server 2008 for x646.6
Microsoft Windows Server 2012 Datacenter6.6
Microsoft Windows Server 2012 R2 Datacenter6.6
Microsoft Windows Server 2012 R2 Std6.6
Microsoft Windows Server 2012 Std6.6
Microsoft Windows Server 20166.6
Microsoft Windows Server 20196.6
Microsoft Windows XP Professional6.6
Windows 7 Enterprise 32 bit6.6
Windows 7 Enterprise x646.6
Windows 7 Home Premium 32 bit6.6
Windows 7 Home Premium x646.6
Windows 7 Professional 32 bit6.6
Windows 7 Professional x646.6
Windows 7 Ultimate 32 bit6.6
Windows 7 Ultimate x646.6
Windows Millennium Edition (Me)6.6
Windows Vista6.6
Windows Vista for x646.6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.