![]() | ![]() | ![]() | ![]() | ![]() |
Severity: Medium
Description: If you have an open browser session but then open another session in a different browser, the session in the first browser stays active for a short period of time before you are logged out. This issue occurs when you open the different sessions and you have disabled concurrent sessions by setting the maxConcurrentSessions parameter to 1 for SASLogon.
Potential Impact: Because the previous session is not logged off immediately, it might be possible for an attacker to potentially access the session.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Visual Investigator | Linux for x64 | 10.8 | Viya | ||
SAS System | SAS Viya | Microsoft® Windows® for x64 | 3.5 | Viya | ||
Linux for x64 | 3.5 | Viya |