The SAS® Web Application Server 9.46 contains third-party Java libraries with known vulnerabilities


Severity: High

Description: SAS Web Application Server 9.46 contains these third-party Java libraries with known vulnerabilities:

Potential Impact: The impact might vary by the vulnerabilities. For details, see the CVE links listed in the previous section.

Resolution: To address this problem, you must first upgrade the SAS Web Application Server to version 9.47, and then manually delete the vulnerable JAR files.

Upgrading the SAS Web Application Server to Version 9.47

SAS Web Application Server 9.47 is provided as a release, not as a hot fix. Therefore, to upgrade SAS Web Application Server, you must update the SAS environment using the SAS® 9.4M7 (TS1M7), Rev. 940_22w08 or later.

Product: tcsvr
Version: 9.46
Display Name: SAS Web Application Server
Display Version: 9.46

Removing the Vulnerable JAR Files after Upgrade

Once the SAS environment has been updated with SAS 9.4M7, Rev. 940_22w08 or later, you must manually delete the bcprov-jdk15on-1.65.jar and httpclient-4.5.12.jar files from the following locations: