The SAS® 9.4 middle-tier services contain Apache Commons FileUpload components that are vulnerable to CVE-2016-1000031


Severity: Critical

Description: Multiple SAS® middle-tier components that are included with SAS® 9.4 software [up to and including release 9.4M6 (TS1M6)] contain the Apache commons-file-upload-1.3.3 library that is vulnerable to the situation that is described in CVE-2016-1000031.

Potential Impact: An attacker might execute malicious code remotely on the server.

Remediation Notes: You can safely remove the vulnerable components by removing the following files: