SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 71059: SAS® Fraud Management contains vulnerabilities that allow improper neutralization of CRLF sequences in HTTP headers

DetailsHotfixAboutRate It

Severity: Medium

Description: SAS Fraud Management contains vulnerabilities that allow improper neutralization of CRLF sequences in HTTP headers.

Potential Impact: Malicious input that contains CRLF might be used to split the HTTP response into two responses. The second response can be controlled by the attacker and might be used for a cross-site scripting or a cache poisoning attack.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Fraud ManagementLinux for x646.19.4 TS1M6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.