Sample programs that are supplied with SAS/IntrNet® contain a file inclusion vulnerability


Severity: High

Description: Sample programs that are supplied with SAS/IntrNet contain a file inclusion vulnerability, as described in CVE-2021-41569.

Potential Impact: An unauthorized attacker might retrieve sensitive information from the server that hosts SAS/IntrNet.

Mitigation: See Disabling Sample Programs in the product documentation.