SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68662: A broken access-control vulnerability occurs with SAS® Anti-Money Laundering REST service endpoints

DetailsHotfixAboutRate It

Severity: Medium

Description: A broken access-control vulnerability can occur in the SAS Anti-Money Laundering REST endpoints.

Potential Impact: Unauthorized users can view entity detail information.

Click the Hot Fix tab in this note to access the hot fix for this issue.

This security vulnerability is fixed in Hot Fix 14 (A5T018).



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Anti-Money LaunderingMicrosoft® Windows® for x647.18.19.4 TS1M6Viya
64-bit Enabled AIX7.18.19.4 TS1M6Viya
64-bit Enabled Solaris7.18.19.4 TS1M6Viya
Linux for x647.18.19.4 TS1M6Viya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.