SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68014: SAS® Data Explorer deployments are vulnerable to Server Side Request Forgery (SSRF)

DetailsHotfixAboutRate It

Severity: High

Description: Penetration testing has found that SAS Data Explorer deployments are potentially vulnerable to Server Side Request Forgery attacks.

Potential Impact: An attacker might be able to induce SAS Data Explorer to make HTTP requests to an arbitrary domain.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS ViyaLinux for x643.42021.1ViyaViya
Microsoft Windows Server 2012 Std3.43.5ViyaViya
Microsoft Windows Server 2012 R2 Std3.43.5ViyaViya
Microsoft Windows Server 2012 Datacenter3.43.5ViyaViya
Microsoft Windows Server 2008 for x643.43.5ViyaViya
Microsoft Windows 103.43.5ViyaViya
Microsoft Windows 8.1 Pro x643.43.5ViyaViya
Microsoft Windows 8.1 Enterprise x643.43.5ViyaViya
Microsoft Windows Server 2012 R2 Datacenter3.43.5ViyaViya
Microsoft Windows 8 Enterprise x643.43.5ViyaViya
Microsoft® Windows® for x643.43.5ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.