First published: Fri Jun 25 2021(Updated: )
SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAS Environment Manager | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35475 is a vulnerability in SAS Environment Manager 2.5 that allows for XSS attacks through the Name field when creating/editing a server.
CVE-2021-35475 has a severity rating of 5.4, which is considered medium.
CVE-2021-35475 allows an attacker to inject malicious scripts into the Name field when creating/editing a server in SAS Environment Manager 2.5, which can be executed by unsuspecting users accessing the Configuration Properties.
To fix CVE-2021-35475, it is recommended to update SAS Environment Manager to a version that includes a patch or fix provided by the vendor.
More information about CVE-2021-35475 can be found on the official SAS support website.