Problem Note 69999: SASĀ® Visual Investigator 10.8 HF 4 contains a version of jQuery that is known to be affected by the CVE-2022-31160 cross-site scripting vulnerability
Severity: Medium
Description: SAS Visual Investigator 10.8 HF 4 contains a jQuery component that is affected by this known vulnerability, CVE-2022-31160.
Potential Impact: Refer to the CVE record that is listed in the previous section for details. Impacts vary and include the potential for JavaScript code execution by an attacker.
Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.
Operating System and Release Information
SAS System | SAS Visual Investigator (on SAS Viya 3.x) | Linux for x64 | 10.8 | 10.8 | Viya | Viya |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
SAS Visual Investigator 10.8 HF 4 contains a version of jQuery that is known to be affected by the CVE-2022-31160 cross-Site scripting vulnerability. Upgrading to SAS Visual Investigator 10.8 HF 5 circumvents this vulnerability.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2025-02-18 08:55:25 |
Date Created: | 2023-04-03 17:17:53 |