Problem Note 64934: The SAS/GRAPH® Java Applet for Web Servers contains XStream, Groovy, and ICU4J libraries that have known vulnerabilities
Severity: High
Description: The XStream 1.4.10, Groovy 1.7.1.0, and ICU4J 61.1.0.0 libraries that are included with the SAS/GRAPH Java Applet for Web Servers contain known vulnerabilities, including those that are described in the following CVE records:
Potential Impact: See the CVE records for details.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Note: The SAS/GRAPH Java Applet for Web Servers does not use XStream or Groovy, and these libraries are removed by the hot fix. The hot fix updates the ICU4J library to version 63.2.0.0.
Operating System and Release Information
SAS System | SAS/GRAPH Java Applets for Web Servers | Microsoft Windows 8 Pro x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 8 Pro 32-bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
z/OS | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft® Windows® for x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 8 Enterprise 32-bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 8 Enterprise x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 8.1 Enterprise 32-bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 8.1 Enterprise x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 8.1 Pro 32-bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 8.1 Pro x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows 10 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows Server 2012 Datacenter | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows Server 2012 R2 Datacenter | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows Server 2012 R2 Std | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows Server 2012 Std | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows Server 2016 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Microsoft Windows Server 2019 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Enterprise 32 bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Enterprise x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Home Premium 32 bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Home Premium x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Professional 32 bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Professional x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Ultimate 32 bit | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Windows 7 Ultimate x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
64-bit Enabled AIX | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
64-bit Enabled Solaris | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
HP-UX IPF | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Linux for x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
Solaris for x64 | 9.45 | 9.46 | 9.4 TS1M6 | 9.4 TS1M7 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2019-10-16 08:14:26 |
Date Created: | 2019-10-15 09:55:21 |