SAS® Anti-Money Laundering supports a version of Apache Solr with known vulnerabilities


Severity: Critical

Description: Apache Solr 5.5.5, which is supported by SAS Anti-Money Laundering 7.1, contains the vulnerabilities described in the following CVE records:

Potential Impact: The impact varies, but it includes remote code execution. See the CVE records for details.

Solution: SAS recommends upgrading to Solr 8.6.2. For installation and usage information, see SAS Note 66795, "Instructions for installing and using Apache Solr 8.6.2 in SAS® Anti-Money Laundering 7.1."