The SAS Viya® 3.5 SAS/GRAPH component contains Spring libraries with known vulnerabilities


Severity: Critical

Description: The SAS Viya 3.5 SAS/GRAPH component contains Spring libraries with known vulnerabilities. The vulnerabilities include, but are not limited to the following:

The impacted files are as follows:

/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-security-web.jar

/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-security-cas.jar

/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-ws-core.jar

/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-xml.jar

Potential Impact: Refer to CVE records listed in the previous section for details.

Solution: You can safely delete the impacted files from the system, because they are not used by SAS.