The SAS® 9.4 Web Infrastructure Platform contains a remote-code execution vulnerability


Severity: Critical

Description: The SAS 9.4 Web Infrastructure Platform is vulnerable to remote code execution via a Java de-serialization variant.

Potential Impact: Attackers can execute code on the server.

The remediation of this issue depends on the maintenance level of the affected SAS 9.4 software, as follows: