![]() | ![]() | ![]() | ![]() | ![]() |
Severity: Medium
Description: SAS Model Studio in SAS® Viya® 3.5 contains a vulnerable version of the third-party JavaScript library CKEditor (4.11.2).
Potential Impact: Users might unknowingly execute malicious code.
Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Viya | Linux for x64 | 3.5 | 2021.1.1 | Viya | Viya |
Microsoft® Windows® for x64 | 3.5 | 2021.1.1 | Viya | Viya |