SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68574: SAS® Web Application Server 9.46 with Hot Fix I9U001 installed contains a vulnerable version of JUnit

DetailsAboutRate It

Severity: Medium

Description: SAS Web Application Server 9.46 contains a vulnerable version of JUnit (JUnit 4.10) if you applied Hot Fix I9U001. The JUnit file is saved in the following location: <SASHome>/SASWebApplicationServer/9.4/lib/junit-4.10.jar

This JAR file is not used by the SAS Web Application Server, but it contains a known vulnerability: CVE-2020-15250

Potential Impact: This is an information disclosure vulnerability. See CVE-2020-15250 for details.

To address this issue, complete these steps:

  1. Stop the SAS Web Application Server.
  2. Remove <SASHome>/SASWebApplicationServer/9.4/lib/junit-4.10.jar from the file system.
  3. Restart the SAS Web Application Server.


Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Application ServerSolaris for x649.469.479.4 TS1M79.4 TS1M8
Linux for x649.469.479.4 TS1M79.4 TS1M8
HP-UX IPF9.469.479.4 TS1M79.4 TS1M8
64-bit Enabled Solaris9.469.479.4 TS1M79.4 TS1M8
64-bit Enabled AIX9.469.479.4 TS1M79.4 TS1M8
Microsoft® Windows® for x649.469.479.4 TS1M79.4 TS1M8
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.