<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cleartext Submission of Password - SAS 9.4 M8 - SAS Login Page in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Cleartext-Submission-of-Password-SAS-9-4-M8-SAS-Login-Page/m-p/984627#M30732</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recently completed a Vulnerability Assessment for a SAS 9.4 M8 environment that includes SAS Visual Analytics and SAS Data Management components.&lt;/P&gt;
&lt;P&gt;The security team used Burp Suite to perform the scan and reported a vulnerability titled “Cleartext Submission of Password” on the SAS VA login page (SASLogon) with High severity.&lt;/P&gt;
&lt;P&gt;The recommendation provided by the security team is:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;Implement salted SHA-256 or salted SHA-512 hashing algorithms on password fields, while using plain SHA-256 or SHA-512 hashing on new password fields.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I reviewed the available SAS documentation but could not find any configuration changes within SAS 9.4 M8 that would allow modification of how passwords are transmitted from the SASLogon login form.&lt;/P&gt;
&lt;P&gt;Has anyone encountered a similar finding during a security assessment of a SAS environment? If so, I would appreciate any guidance or recommendations on how this vulnerability can be mitigated or addressed.&lt;/P&gt;
&lt;P&gt;Any assistance or insights would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/28909"&gt;@AllanBowe&lt;/a&gt;&amp;nbsp; &amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13527"&gt;@CVitron&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/386"&gt;@Mark_sas&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/1540"&gt;@ronan&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/422172"&gt;@kimberlymay&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/463721"&gt;@RyanKing&lt;/a&gt;&amp;nbsp; : Any help from you experts will make a huge impact.&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;Abhishek Pathak&lt;/P&gt;</description>
    <pubDate>Thu, 12 Mar 2026 05:47:23 GMT</pubDate>
    <dc:creator>avvy</dc:creator>
    <dc:date>2026-03-12T05:47:23Z</dc:date>
    <item>
      <title>Cleartext Submission of Password - SAS 9.4 M8 - SAS Login Page</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Cleartext-Submission-of-Password-SAS-9-4-M8-SAS-Login-Page/m-p/984627#M30732</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recently completed a Vulnerability Assessment for a SAS 9.4 M8 environment that includes SAS Visual Analytics and SAS Data Management components.&lt;/P&gt;
&lt;P&gt;The security team used Burp Suite to perform the scan and reported a vulnerability titled “Cleartext Submission of Password” on the SAS VA login page (SASLogon) with High severity.&lt;/P&gt;
&lt;P&gt;The recommendation provided by the security team is:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;Implement salted SHA-256 or salted SHA-512 hashing algorithms on password fields, while using plain SHA-256 or SHA-512 hashing on new password fields.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I reviewed the available SAS documentation but could not find any configuration changes within SAS 9.4 M8 that would allow modification of how passwords are transmitted from the SASLogon login form.&lt;/P&gt;
&lt;P&gt;Has anyone encountered a similar finding during a security assessment of a SAS environment? If so, I would appreciate any guidance or recommendations on how this vulnerability can be mitigated or addressed.&lt;/P&gt;
&lt;P&gt;Any assistance or insights would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/28909"&gt;@AllanBowe&lt;/a&gt;&amp;nbsp; &amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/13527"&gt;@CVitron&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/386"&gt;@Mark_sas&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/1540"&gt;@ronan&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/422172"&gt;@kimberlymay&lt;/a&gt;&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/463721"&gt;@RyanKing&lt;/a&gt;&amp;nbsp; : Any help from you experts will make a huge impact.&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;
&lt;P&gt;Abhishek Pathak&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 05:47:23 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Cleartext-Submission-of-Password-SAS-9-4-M8-SAS-Login-Page/m-p/984627#M30732</guid>
      <dc:creator>avvy</dc:creator>
      <dc:date>2026-03-12T05:47:23Z</dc:date>
    </item>
  </channel>
</rss>

