The SASĀ® 9.4 Cache Locator service contains SpringSource Spring Framework libraries with known vulnerabilities


Severity: Critical

Description: The Cache Locator service that is included with SAS 9.4 software up to and including release 9.4M6 (TS1M6) contains the spring-security-ldap-3.1.4 library. This library is vulnerable to issues that are described ion the following CVEs:

Potential Impact: An attacker might bypass authentication mechanisms that use the affected Spring Framework library.

Remediation Notes: You can remove the vulnerable component safely by following these steps:

  1. Navigate to SAS-configuration-directory/Lev1/Web/gemfire/tools/Pulse on the SAS server where the SAS Cache Locator service resides.
  2. Delete the pulse.war file.
  3. Restart the Cache Locator service.