SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 69386: SAS® Business Data Network 3.3 contains a cross-site scripting (XSS) vulnerability

DetailsHotfixAboutRate It

Severity: Medium

Description: The Terms menu in SAS Business Data Network 3.3 contains a cross-site scripting (XSS) vulnerability that allows JavaScript to be embedded in a certain property. 

Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Business Data NetworkSolaris for x643.33.49.4 TS1M69.4 TS1M8
Linux for x643.33.49.4 TS1M69.4 TS1M8
HP-UX IPF3.33.49.4 TS1M69.4 TS1M8
64-bit Enabled Solaris3.33.49.4 TS1M69.4 TS1M8
64-bit Enabled AIX3.33.49.4 TS1M69.4 TS1M8
Microsoft® Windows® for x643.33.49.4 TS1M69.4 TS1M8
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.