A new update is available for SAS BI Report Services , version 4.4_M3 :
SAS Note 62192 | In SAS® Web Report Studio, the report name field contains a cross-site scripting vulnerability |
SAS Note 62499 | In SAS® Web Report Studio, the section name field contains a cross-site scripting vulnerability |
SAS Note 62876 | SAS® Web Report Studio images contain a cross-site scripting vulnerability |
SAS Note 62972 | SAS® Web Report Studio URL has a cross-site scripting vulnerability |
This list of notes might be incomplete. For a complete list of issues addressed by this hot fix, visit the hot fix page for V66008 |
Note: A comprehensive list of all SAS hot fixes is available from support.sas.com. You can use the SAS Hot Fix Analysis, Download, and Deployment (SASHFADD) tool to manage your SAS hot fixes.