SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70042: SAS® Web Application Server contains a version of Tomcat that is affected by CVE-2023-24998

DetailsHotfixAboutRate It

Severity: High

Description: SAS Web Application Server contains a version of Tomcat that is affected by CVE-2023-24998.

Potential Impact: Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed, which results in the possibility of an attacker triggering a DoS with a malicious upload or a series of uploads.

Click the Hot Fix tab in this note to access the hot fix for this issue. 

 



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Application ServerMicrosoft® Windows® for x649.469.4 TS1M7
64-bit Enabled AIX9.469.4 TS1M7
64-bit Enabled Solaris9.469.4 TS1M7
HP-UX IPF9.469.4 TS1M7
Linux for x649.469.4 TS1M7
Solaris for x649.469.4 TS1M7
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.