![]() | ![]() | ![]() | ![]() |
Severity: High
Description: SAS Web Application Server 9.46 contains these third-party Java libraries with known vulnerabilities:
Potential Impact: The impact might vary by the vulnerabilities. For details, see the CVE links listed in the previous section.
Resolution: To address this problem, you must first upgrade the SAS Web Application Server to version 9.47, and then manually delete the vulnerable JAR files.
SAS Web Application Server 9.47 is provided as a release, not as a hot fix. Therefore, to upgrade SAS Web Application Server, you must update the SAS environment using the SAS® 9.4M7 (TS1M7), Rev. 940_22w08 or later.
Once the SAS environment has been updated with SAS 9.4M7, Rev. 940_22w08 or later, you must manually delete the bcprov-jdk15on-1.65.jar and httpclient-4.5.12.jar files from the following locations:
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Web Application Server | Solaris for x64 | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |
Linux for x64 | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 | ||
HP-UX IPF | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 | ||
64-bit Enabled Solaris | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 | ||
64-bit Enabled AIX | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 | ||
Microsoft® Windows® for x64 | 9.46 | 9.47 | 9.4 TS1M7 | 9.4 TS1M7 |