SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68453: SAS® Risk and Finance Workbench contains a user security vulnerability

DetailsHotfixAboutRate It

Severity: Low

Description: In SAS Risk and Finance Workbench, a non-admin user who cannot view the Configuration menu in the SAS Risk and Finance Workbench user interface is able to create a new Dimension category through the REST API.

Potential Impact: Non-admin users might create a Dimension category in SAS Risk and Finance Workbench.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Risk and Finance WorkbenchLinux for x643.19.4 TS1M5
Microsoft® Windows® for x643.19.4 TS1M5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.