![]() | ![]() | ![]() | ![]() | ![]() |
Severity: High
Description: SAS Customer Intelligence Studio contains a version of the BlazeDS component that is affected by the vulnerability that is described in CVE 2017-3066.
Potential Impact: An attacker can use this vulnerability as a first stage of attack that can lead to remote code execution. Remote code execution can occur if the software is not patched against the Java deserialization vulnerability that is described in SAS Statement Regarding Java Deserialization Vulnerability.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Customer Intelligence Studio | Microsoft® Windows® for x64 | 6.5 | 9.4 TS1M4 | ||
Microsoft Windows 8 Enterprise 32-bit | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 8 Enterprise x64 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 8 Pro 32-bit | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 8 Pro x64 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 8.1 Enterprise 32-bit | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 8.1 Enterprise x64 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 8.1 Pro 32-bit | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 8.1 Pro x64 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows 10 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows Server 2008 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows Server 2008 R2 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows Server 2008 for x64 | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows Server 2012 Datacenter | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows Server 2012 R2 Datacenter | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows Server 2012 R2 Std | 6.5 | 9.4 TS1M4 | ||||
Microsoft Windows Server 2012 Std | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Enterprise 32 bit | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Enterprise x64 | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Home Premium 32 bit | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Home Premium x64 | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Professional 32 bit | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Professional x64 | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Ultimate 32 bit | 6.5 | 9.4 TS1M4 | ||||
Windows 7 Ultimate x64 | 6.5 | 9.4 TS1M4 | ||||
64-bit Enabled AIX | 6.5 | 9.4 TS1M4 | ||||
64-bit Enabled Solaris | 6.5 | 9.4 TS1M4 | ||||
HP-UX IPF | 6.5 | 9.4 TS1M4 | ||||
Linux for x64 | 6.5 | 9.4 TS1M4 | ||||
Solaris for x64 | 6.5 | 9.4 TS1M4 |