SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68945: The SAS® Stored Process Web Application contains a reflected cross-site scripting (XSS) vulnerability

DetailsHotfixAboutRate It

Severity: Medium

Description: The SAS Stored Process Web Application contains a reflected cross-site scripting (XSS) vulnerability that allows JavaScript code to be injected via a certain query parameter and executed on browser.

Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Infrastructure PlatformMicrosoft® Windows® for x649.4_M69.4_M89.4 TS1M69.4 TS1M8
64-bit Enabled AIX9.4_M69.4_M89.4 TS1M69.4 TS1M8
64-bit Enabled Solaris9.4_M69.4_M89.4 TS1M69.4 TS1M8
HP-UX IPF9.4_M69.4_M89.4 TS1M69.4 TS1M8
Linux for x649.4_M69.4_M89.4 TS1M69.4 TS1M8
Solaris for x649.4_M69.4_M89.4 TS1M69.4 TS1M8
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.