CVE-2015-9281: XSS
Published Jan 17, 2019
·Updated
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
Affected Software
12 affected components
SAS Web Infrastructure Platform<9.4
SAS Web Infrastructure Platform=9.4
SAS Web Infrastructure Platform=9.4-maintenance_release_1
SAS Web Infrastructure Platform=9.4-maintenance_release_2
SAS Web Infrastructure Platform=9.4-maintenance_release_3
SAS Web Infrastructure Platform=9.4-maintenance_release_4
SAS Web Infrastructure Platform=9.4-maintenance_release_5
HPE Hp-ux Ipfilter
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Jan 17, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2015-9281.
2
What is the severity of CVE-2015-9281?
The severity of CVE-2015-9281 is medium with a severity value of 6.1.
3
Which SAS Web Infrastructure Platform versions are affected?
SAS Web Infrastructure Platform versions up to and including 9.4 are affected.
4
What is the impact of CVE-2015-9281?
CVE-2015-9281 allows for reflected Cross-Site Scripting (XSS) attacks on the Timeout page of SAS Web Infrastructure Platform.
5
Is there a fix available for CVE-2015-9281?
Yes, a fix is available for CVE-2015-9281. Please refer to the SAS support website for more information.