SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 71095: SAS® Customer Intelligence 6.6 contains an authorization bypass vulnerability

DetailsHotfixAboutRate It

Severity: Low

Description: A user might be able to set and change campaign permissions despite a message in the user interface that says the user is not authorized to change it.

Potential Impact: Permissions on campaign objects might be changed outside SAS Customer Intelligence Studio 6.6. 

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Customer Intelligence StudioMicrosoft Windows Server 20196.6
Microsoft Windows Server 20166.6
Microsoft Windows Server 2012 Std6.6
Microsoft Windows Server 2012 R2 Std6.6
Microsoft Windows Server 2012 R2 Datacenter6.6
Microsoft Windows Server 2012 Datacenter6.6
Microsoft Windows Server 2008 for x646.6
Microsoft Windows Server 2008 R26.6
Microsoft Windows Server 20086.6
Microsoft Windows Server 2003 for x646.6
Microsoft Windows Server 2003 Standard Edition6.6
Microsoft Windows Server 2003 Enterprise Edition6.6
Microsoft Windows Server 2003 Datacenter Edition6.6
Microsoft Windows NT Workstation6.6
Microsoft Windows 2000 Professional6.6
Microsoft Windows 2000 Server6.6
Microsoft Windows 2000 Datacenter Server6.6
Microsoft Windows 2000 Advanced Server6.6
Microsoft Windows 95/986.6
Microsoft Windows 116.6
Microsoft Windows 106.6
Microsoft Windows 8.1 Pro x646.6
Microsoft Windows 8.1 Pro 32-bit6.6
Microsoft Windows 8.1 Enterprise x646.6
Microsoft Windows 8.1 Enterprise 32-bit6.6
Microsoft Windows 8 Pro x646.6
Microsoft Windows 8 Pro 32-bit6.6
Microsoft Windows 8 Enterprise x646.6
Microsoft Windows 8 Enterprise 32-bit6.6
Microsoft® Windows® for x646.6
Microsoft Windows Server 20226.6
Microsoft Windows XP Professional6.6
Windows 7 Enterprise 32 bit6.6
Windows 7 Enterprise x646.6
Windows 7 Home Premium 32 bit6.6
Windows 7 Home Premium x646.6
Windows 7 Professional 32 bit6.6
Windows 7 Professional x646.6
Windows 7 Ultimate 32 bit6.6
Windows 7 Ultimate x646.6
Windows Millennium Edition (Me)6.6
Windows Vista6.6
Windows Vista for x646.6
64-bit Enabled AIX6.6
64-bit Enabled Solaris6.6
HP-UX IPF6.6
Linux for x646.6
Solaris for x646.6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.