Severity: Critical
Description: The Cache Locator service that is included with SAS 9.4 software up to and including release 9.4M6 (TS1M6) contains the spring-security-ldap-3.1.4 library. This library is vulnerable to issues that are described ion the following CVEs:
Potential Impact: An attacker might bypass authentication mechanisms that use the affected Spring Framework library.
Remediation Notes: You can remove the vulnerable component safely by following these steps: