SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 62379: SAS® Workflow Studio is dependent on a version of Apache POI that contains a security vulnerability

DetailsHotfixAboutRate It

Severity: High

Description: SAS Workflow Studio contains a dependency on Apache POI. Versions of Apache POI prior to release 3.15 allow remote attackers to cause a denial of service (CPU consumption). The remote attack potentially uses a specially crafted OOXML file, also known as an XML Entity Expansion (XEE) attack.

Potential Impact: There is a total shutdown of the affected resource. The attacker can render the resource completely unavailable.

For additional details see: CVE-2017-5644

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Workflow StudioMicrosoft® Windows® for x641.3_M49.4 TS1M4
Microsoft Windows 8 Enterprise 32-bit1.3_M49.4 TS1M4
Microsoft Windows 8 Enterprise x641.3_M49.4 TS1M4
Microsoft Windows 8 Pro 32-bit1.3_M49.4 TS1M4
Microsoft Windows 8 Pro x641.3_M49.4 TS1M4
Microsoft Windows 8.1 Enterprise 32-bit1.3_M49.4 TS1M4
Microsoft Windows 8.1 Enterprise x641.3_M49.4 TS1M4
Microsoft Windows 8.1 Pro 32-bit1.3_M49.4 TS1M4
Microsoft Windows 8.1 Pro x641.3_M49.4 TS1M4
Microsoft Windows 101.3_M49.4 TS1M4
Microsoft Windows Server 20081.3_M49.4 TS1M4
Microsoft Windows Server 2008 R21.3_M49.4 TS1M4
Microsoft Windows Server 2008 for x641.3_M49.4 TS1M4
Microsoft Windows Server 2012 Datacenter1.3_M49.4 TS1M4
Microsoft Windows Server 2012 R2 Datacenter1.3_M49.4 TS1M4
Microsoft Windows Server 2012 R2 Std1.3_M49.4 TS1M4
Microsoft Windows Server 2012 Std1.3_M49.4 TS1M4
Windows 7 Enterprise 32 bit1.3_M49.4 TS1M4
Windows 7 Enterprise x641.3_M49.4 TS1M4
Windows 7 Home Premium 32 bit1.3_M49.4 TS1M4
Windows 7 Home Premium x641.3_M49.4 TS1M4
Windows 7 Professional 32 bit1.3_M49.4 TS1M4
Windows 7 Professional x641.3_M49.4 TS1M4
Windows 7 Ultimate 32 bit1.3_M49.4 TS1M4
Windows 7 Ultimate x641.3_M49.4 TS1M4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.