Severity: Low
Description: The Help content for SAS Infrastructure for Risk Management contains mixed HTTP and HTTPS content.
Potential Impact: A MITM (Man-In-The-Middle) attack might be possible, enabling manipulation of unencrypted content in the response.
-
- Click rqsst_doc.zip to access the fix for this issue and follow the instructions to update the system.
- Start SAS® Management Console and connect to the appropriate metadata server as a SAS administrator (for example, sasadm@saspw).
- On the Plug-ins tab, verify that the repository is selected in the Repository field. The default repository is Foundation.
- Select Application Management ► Configuration Manager ► SAS Application Infrastructure.
- In the main pane, right-click SAS IRM Mid-Tier Server and select Properties. The IRM Mid-Tier Server Properties window is displayed.
- Click the Advanced tab to see the list of federated areas similar to the ones below.

- There should be a property in this list named com.sas.solutions.risk.irm.fa.st.2021.08. The property value is the location where SAS® Solution for Stress Testing is deployed. Note this path.
- Navigate to the root path listed in the previous step. In this root folder, there should be a folder named doc under the /irm folder. Extract the attached ZIP folder into the /irm folder in order to overwrite the /irm/doc folder and its contents.
- After unzipping the file, verify that you no longer see any references to HTTP in your Doxygen documentation.