The Help content for SAS® Infrastructure for Risk Management contains mixed HTTP and HTTPS content


Severity: Low

Description: The Help content for SAS Infrastructure for Risk Management contains mixed HTTP and HTTPS content.

Potential Impact: A MITM (Man-In-The-Middle) attack might be possible, enabling manipulation of unencrypted content in the response.

    1. Click rqsst_doc.zip to access the fix for this issue and follow the instructions to update the system.
    2. Start SAS® Management Console and connect to the appropriate metadata server as a SAS administrator (for example, sasadm@saspw).
    3. On the Plug-ins tab, verify that the repository is selected in the Repository field. The default repository is Foundation.
    4. Select Application Management ► Configuration Manager ► SAS Application Infrastructure.
    5. In the main pane, right-click SAS IRM Mid-Tier Server and select Properties. The IRM Mid-Tier Server Properties window is displayed.
    6. Click the Advanced tab to see the list of federated areas similar to the ones below.
    7. There should be a property in this list named com.sas.solutions.risk.irm.fa.st.2021.08. The property value is the location where SAS® Solution for Stress Testing is deployed. Note this path.
    8. Navigate to the root path listed in the previous step. In this root folder, there should be a folder named doc under the /irm folder. Extract the attached ZIP folder into the /irm folder in order to overwrite the /irm/doc folder and its contents.
    9. After unzipping the file, verify that you no longer see any references to HTTP in your Doxygen documentation.