SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 62682: SAS® Model Risk Management and SAS® Enterprise GRC include a version of Apache POI that contains security vulnerabilities

DetailsHotfixAboutRate It

Severity: High

Description: Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption). The remote attack potentially uses a specially crafted OOXML file, also known as an XML Entity Expansion (XEE) attack.

Potential Impact:  There is a total shutdown of the affected resource. The attacker can render the resource completely unavailable.

For additional details see: CVE-2017-5644

Description: Apache POI in versions prior to release 3.17 are vulnerable to the following Denial of Service Attacks:

  1. Infinite Loops while parsing crafted WMF, EMF, MSG, and macros (POI bugs 61338 and 61294), and
  2. Out of Memory Exceptions while parsing crafted DOC, PPT, and XLS (POI bugs 52372 and 61295).

Potential Impact: There is reduced performance or interruptions in resource availability.

For additional details see: CVE-2017-12626

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Model Risk ManagementMicrosoft® Windows® for x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Enterprise 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Enterprise x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Pro 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8 Pro x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Enterprise 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Enterprise x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Pro 32-bit6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 8.1 Pro x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows 106.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 20086.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2008 R26.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2008 for x646.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 Datacenter6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 R2 Datacenter6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 R2 Std6.17.49.4 TS1M29.4 TS1M5
Microsoft Windows Server 2012 Std6.17.49.4 TS1M29.4 TS1M5
Windows 7 Enterprise 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Enterprise x646.17.49.4 TS1M29.4 TS1M5
Windows 7 Home Premium 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Home Premium x646.17.49.4 TS1M29.4 TS1M5
Windows 7 Professional 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Professional x646.17.49.4 TS1M29.4 TS1M5
Windows 7 Ultimate 32 bit6.17.49.4 TS1M29.4 TS1M5
Windows 7 Ultimate x646.17.49.4 TS1M29.4 TS1M5
64-bit Enabled AIX6.17.49.4 TS1M29.4 TS1M5
64-bit Enabled Solaris6.17.49.4 TS1M29.4 TS1M5
HP-UX IPF6.17.49.4 TS1M29.4 TS1M5
Linux for x646.17.49.4 TS1M29.4 TS1M5
Solaris for x646.17.49.4 TS1M29.4 TS1M5
SAS SystemSAS Enterprise GRCWindows 7 Home Premium x645.1_M59.3 TS1M2
Windows 7 Home Premium 32 bit5.1_M59.3 TS1M2
Windows 7 Enterprise x645.1_M59.3 TS1M2
Windows 7 Enterprise 32 bit5.1_M59.3 TS1M2
Microsoft Windows XP Professional5.1_M59.3 TS1M2
Microsoft Windows Server 2012 Std5.1_M59.3 TS1M2
Microsoft Windows Server 2012 R2 Std5.1_M59.3 TS1M2
Microsoft Windows Server 2012 R2 Datacenter5.1_M59.3 TS1M2
Microsoft Windows Server 2012 Datacenter5.1_M59.3 TS1M2
Microsoft Windows Server 2008 for x645.1_M59.3 TS1M2
Microsoft Windows Server 2008 R25.1_M59.3 TS1M2
Microsoft Windows Server 20085.1_M59.3 TS1M2
Microsoft Windows Server 2003 for x645.1_M59.3 TS1M2
Microsoft Windows Server 2003 Standard Edition5.1_M59.3 TS1M2
Microsoft Windows Server 2003 Enterprise Edition5.1_M59.3 TS1M2
Microsoft Windows Server 2003 Datacenter Edition5.1_M59.3 TS1M2
Microsoft Windows 8.1 Pro x645.1_M59.3 TS1M2
Microsoft Windows 8.1 Pro 32-bit5.1_M59.3 TS1M2
Microsoft Windows 8.1 Enterprise x645.1_M59.3 TS1M2
Microsoft Windows 8.1 Enterprise 32-bit5.1_M59.3 TS1M2
Microsoft Windows 8 Pro x645.1_M59.3 TS1M2
Microsoft Windows 8 Pro 32-bit5.1_M59.3 TS1M2
Microsoft Windows 8 Enterprise x645.1_M59.3 TS1M2
Microsoft Windows 8 Enterprise 32-bit5.1_M59.3 TS1M2
Microsoft® Windows® for x645.1_M59.3 TS1M2
Windows 7 Professional 32 bit5.1_M59.3 TS1M2
Windows 7 Professional x645.1_M59.3 TS1M2
Windows 7 Ultimate 32 bit5.1_M59.3 TS1M2
Windows 7 Ultimate x645.1_M59.3 TS1M2
Windows Vista5.1_M59.3 TS1M2
Windows Vista for x645.1_M59.3 TS1M2
64-bit Enabled AIX5.1_M59.3 TS1M2
64-bit Enabled Solaris5.1_M59.3 TS1M2
HP-UX IPF5.1_M59.3 TS1M2
Linux for x645.1_M59.3 TS1M2
Solaris for x645.1_M59.3 TS1M2
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.