SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 69999: SAS® Visual Investigator 10.8 HF 4 contains a version of jQuery that is known to be affected by the CVE-2022-31160 cross-site scripting vulnerability

DetailsHotfixAboutRate It

Severity: Medium

Description: SAS Visual Investigator 10.8 HF 4 contains a jQuery component that is affected by this known vulnerability, CVE-2022-31160.

Potential Impact: Refer to the CVE record that is listed in the previous section for details. Impacts vary and include the potential for JavaScript code execution by an attacker.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual Investigator (on SAS Viya 3.x)Linux for x6410.810.8ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.