SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70876: SAS® Visual Analytics 7.51 and 7.52 contain a stored cross-site scripting (XSS) vulnerability

DetailsHotfixAboutRate It

Severity: High

Description: SAS Visual Analytics 7.51 and 7.52 contain a stored cross-site scripting (XSS) vulnerability that allows JavaScript code to be injected via a certain POST request and executed on browser.

Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.

 



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual Analytics (on SAS 9.x)Microsoft® Windows® for x647.517.529.4 TS1M79.4 TS1M8
Linux for x647.517.529.4 TS1M79.4 TS1M8
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.