Problem Note 68897: The SAS® Web Application Server 9.46 contains third-party Java libraries with known vulnerabilities
Severity: High
Description: SAS Web Application Server 9.46 contains these third-party Java libraries with known vulnerabilities:
- CVE-2020-28052: Bouncy Castle Crypto package 1.65 (bcprov-jdk15on-1.65.jar)
- CVE-2020-13956: Apache HttpClient 4.5.12 (httpclient-4.5.12.jar)
Potential Impact: The impact might vary by the vulnerabilities. For details, see the CVE links listed in the previous section.
Resolution: To address this problem, you must first upgrade the SAS Web Application Server to version 9.47, and then manually delete the vulnerable JAR files.
Upgrading the SAS Web Application Server to Version 9.47
SAS Web Application Server 9.47 is provided as a release, not as a hot fix. Therefore, to upgrade SAS Web Application Server, you must update the SAS environment using the SAS® 9.4M7 (TS1M7), Rev. 940_22w08 or later.
- To check the currently installed SAS Web Application Server version, follow the instructions in SAS KB0036131 to generate the registry report (DeploymentRegistry.txt) in the middle-tier server. In the registry report, the version number is listed in the Version field of the product tcsvr as shown below. If the version number is 9.46 or lower, you need to upgrade to 9.47:
Product: tcsvr
Version: 9.46
Display Name: SAS Web Application Server
Display Version: 9.46
Removing the Vulnerable JAR Files after Upgrade
Once the SAS environment has been updated with SAS 9.4M7, Rev. 940_22w08 or later, you must manually delete the bcprov-jdk15on-1.65.jar and httpclient-4.5.12.jar files from the following locations:
- SASHome/SASWebApplicationServer/9.4/tomcat-7.0.106.A.RELEASE/
- SASHome/SASWebApplicationServer/9.4/tomcat-8.5.58.B.RELEASE/
- SASHome/SASWebApplicationServer/9.4-1/9.4/
- SASHome/SASWebApplicationServerBackup[date]/
Operating System and Release Information
SAS System | SAS Web Application Server | Solaris for x64 | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |
Linux for x64 | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |
HP-UX IPF | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |
64-bit Enabled Solaris | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |
64-bit Enabled AIX | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |
Microsoft® Windows® for x64 | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2022-02-24 07:29:08 |
Date Created: | 2022-02-08 02:09:30 |