SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 67872: SAS® Model Studio contains a version of CKEditor with known vulnerabilities

DetailsHotfixAboutRate It

Severity: Medium

Description: SAS Model Studio in SAS® Viya® 3.5 contains a vulnerable version of the third-party JavaScript library CKEditor (4.11.2).

Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS ViyaLinux for x643.52021.1.1ViyaViya
Microsoft® Windows® for x643.52021.1.1ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.