Severity: Critical
Description: The SAS Viya 3.5 SAS/GRAPH component contains Spring libraries with known vulnerabilities. The vulnerabilities include, but are not limited to the following:
The impacted files are as follows:
/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-security-web.jar
/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-security-cas.jar
/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-ws-core.jar
/opt/sas/spre/home/SASFoundation/lib/graph/graphjars/spring-xml.jar
Potential Impact: Refer to CVE records listed in the previous section for details.
Solution: You can safely delete the impacted files from the system, because they are not used by SAS.