Logon Manager in SAS Web Infrastructure Platform prior to 9.4M3 allows reflected XSS on the Timeout page.
sas web_infrastructure_platform
sas web_infrastructure_platform 9.4