SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 69444: The SAS® Risk Governance Framework contains a cross-site scripting vulnerability

DetailsHotfixAboutRate It

Severity: Medium

Description: SAS Risk Governance Framework contains a cross-site scripting vulnerability in its Comments feature.

Potential Impact: A user might unknowingly execute malicious code.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Risk Governance FrameworkMicrosoft® Windows® for x647.4
Microsoft Windows 8 Enterprise 32-bit7.4
Microsoft Windows 8 Enterprise x647.4
Microsoft Windows 8 Pro 32-bit7.4
Microsoft Windows 8 Pro x647.4
Microsoft Windows 8.1 Enterprise 32-bit7.4
Microsoft Windows 8.1 Enterprise x647.4
Microsoft Windows 8.1 Pro 32-bit7.4
Microsoft Windows 8.1 Pro x647.4
Microsoft Windows 107.4
Microsoft Windows 117.4
Microsoft Windows 95/987.4
Microsoft Windows 2000 Advanced Server7.4
Microsoft Windows 2000 Datacenter Server7.4
Microsoft Windows 2000 Server7.4
Microsoft Windows 2000 Professional7.4
Microsoft Windows NT Workstation7.4
Microsoft Windows Server 2003 Datacenter Edition7.4
Microsoft Windows Server 2003 Enterprise Edition7.4
Microsoft Windows Server 2003 Standard Edition7.4
Microsoft Windows Server 2003 for x647.4
Microsoft Windows Server 20087.4
Microsoft Windows Server 2008 R27.4
Microsoft Windows Server 2008 for x647.4
Microsoft Windows Server 2012 Datacenter7.4
Microsoft Windows Server 2012 R2 Datacenter7.4
Microsoft Windows Server 2012 R2 Std7.4
Microsoft Windows Server 2012 Std7.4
Microsoft Windows Server 20167.4
Microsoft Windows Server 20197.4
Microsoft Windows Server 20227.4
Microsoft Windows XP Professional7.4
Windows 7 Enterprise 32 bit7.4
Windows 7 Enterprise x647.4
Windows 7 Home Premium 32 bit7.4
Windows 7 Home Premium x647.4
Windows 7 Professional 32 bit7.4
Windows 7 Professional x647.4
Windows 7 Ultimate 32 bit7.4
Windows 7 Ultimate x647.4
Windows Millennium Edition (Me)7.4
Windows Vista7.4
Windows Vista for x647.4
Linux for x647.4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.