Problem Note 63391: The SAS® 9.4 Web Infrastructure Platform contains a remote-code execution vulnerability
Severity: Critical
Description: The SAS 9.4 Web Infrastructure Platform is vulnerable to remote code execution via a Java de-serialization variant.
Potential Impact: Attackers can execute code on the server.
The remediation of this issue depends on the maintenance level of the affected SAS 9.4 software, as follows:
- SAS 9.4M6 (TS1M6): No action is required. The issue resolved in this release.
- SAS 9.4M5 (TS1M5): Apply the SAS® Security Update for 9.4M5.
- SAS 9.4M4 (TS1M4) and earlier: Follow the steps below. Note: Replace SAS-configuration-directory in the steps below with the complete path to your SAS configuration folder.
- Ensure that the SAS® software is updated with SAS Security Update 2017-09.
- Download the ZIP file that is on the Downloads tab and extract the serialization.conf file.
- Copy the serialization.conf file to SAS-configuration-directory/Lev1/Web/WebAppServer/SASServer_Y/conf/.
- Add the following JVM argument to the start-up arguments for SASServerX_Y:
-Dhttpinvoker.deserialization.configfile=file:///SAS-configuration-directory/Lev1/Web/WebAppServer/SASServerX_Y/conf/serialization.conf
- Repeat steps 1-3 for any additional SASServerX_Y instances, if the environment is clustered.
- Restart all SAS 9.4 Web Application Server instances.
Operating System and Release Information
SAS System | SAS Web Infrastructure Platform | Microsoft® Windows® for x64 | 9.4 | 9.4_M6 | 9.4 TS1M0 | 9.4 TS1M6 |
HP-UX IPF | 9.4 | 9.4_M6 | 9.4 TS1M0 | 9.4 TS1M6 |
64-bit Enabled Solaris | 9.4 | 9.4_M6 | 9.4 TS1M0 | 9.4 TS1M6 |
64-bit Enabled AIX | 9.4 | 9.4_M6 | 9.4 TS1M0 | 9.4 TS1M6 |
Linux for x64 | 9.4 | 9.4_M6 | 9.4 TS1M0 | 9.4 TS1M6 |
Solaris for x64 | 9.4 | 9.4_M6 | 9.4 TS1M0 | 9.4 TS1M6 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2019-01-11 11:18:33 |
Date Created: | 2018-12-14 14:55:54 |