CVE-2021-35475: XSS
SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-35475?
CVE-2021-35475 is a vulnerability in SAS Environment Manager 2.5 that allows for XSS attacks through the Name field when creating/editing a server.
What is the severity of CVE-2021-35475?
CVE-2021-35475 has a severity rating of 5.4, which is considered medium.
How does CVE-2021-35475 work?
CVE-2021-35475 allows an attacker to inject malicious scripts into the Name field when creating/editing a server in SAS Environment Manager 2.5, which can be executed by unsuspecting users accessing the Configuration Properties.
How can I fix CVE-2021-35475?
To fix CVE-2021-35475, it is recommended to update SAS Environment Manager to a version that includes a patch or fix provided by the vendor.
Where can I get more information about CVE-2021-35475?
More information about CVE-2021-35475 can be found on the official SAS support website.