Problem Note 70362: SAS® Studio (Basic) 3.81 and 3.82 releases contain JAR files with known vulnerabilities
Severity: High
Description: SAS Studio (Basic) 3.82 and SAS Studio (Basic) 3.81 contain JAR files with the following known vulnerabilities:
Click the Hot Fix tab in this note to access the hot fixes for this issue.
As part of the hot fix process, the current JAR files are backed up. After you apply the hot fix, you should remove the backup files so that they do not appear on security scans.
The JAR files will be backed up to the following locations:
On SAS Studio (Basic) 3.82:
<sashome>/SASStudioBasic/3.82/installs/studio_<hot fix identifier>/SASHome/xx/SASStudioBasic/3.82/war/WEB-INF/lib
<sasconfig>/Lev1/Web/WebAppServer/SASServer2_1/sas_webapps/Backup/sas.sasstudio.war.<date>/WEB-INF/lib/
On SAS Studio (Basic) 3.81:
<sashome>/SASStudioBasic/3.81/installs/studio_<hot fix identifier>/SASHome/xx/SASStudioBasic/3.81/war/WEB-INF/lib
<sasconfig>/Lev1/Web/WebAppServer/SASServer2_1/sas_webapps/Backup/sas.sasstudio.war.<date>/WEB-INF/lib/
Operating System and Release Information
SAS System | SAS Studio | Windows 7 Ultimate x64 | 3.81 | | 9.4 TS1M7 | |
Windows 7 Ultimate 32 bit | 3.81 | | 9.4 TS1M7 | |
Windows 7 Professional x64 | 3.81 | | 9.4 TS1M7 | |
Windows 7 Professional 32 bit | 3.81 | | 9.4 TS1M7 | |
Windows 7 Home Premium x64 | 3.81 | | 9.4 TS1M7 | |
Windows 7 Home Premium 32 bit | 3.81 | | 9.4 TS1M7 | |
Windows 7 Enterprise x64 | 3.81 | | 9.4 TS1M7 | |
Windows 7 Enterprise 32 bit | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2022 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2019 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2016 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2012 Std | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2012 R2 Std | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2012 R2 Datacenter | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2012 Datacenter | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2008 for x64 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2008 R2 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows Server 2008 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 11 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 10 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8.1 Pro x64 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8.1 Pro 32-bit | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8.1 Enterprise x64 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8.1 Enterprise 32-bit | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8 Pro x64 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8 Pro 32-bit | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8 Enterprise x64 | 3.81 | | 9.4 TS1M7 | |
Microsoft Windows 8 Enterprise 32-bit | 3.81 | | 9.4 TS1M7 | |
Microsoft® Windows® for x64 | 3.81 | | 9.4 TS1M7 | |
64-bit Enabled AIX | 3.81 | | 9.4 TS1M7 | |
64-bit Enabled Solaris | 3.81 | | 9.4 TS1M7 | |
HP-UX IPF | 3.81 | | 9.4 TS1M7 | |
Linux for x64 | 3.81 | | 9.4 TS1M7 | |
Solaris for x64 | 3.81 | | 9.4 TS1M7 | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2023-12-08 14:24:48 |
Date Created: | 2023-09-08 13:41:33 |