Severity: High
Description: The CLASSPATH LIBNAME option and the SAS_HADOOP_JAR_PATH global option allow path traversal via multiple SAS products including certain SAS/ACCESS® and SAS® Threaded Kernel Extension products.
Potential Impact: This vulnerability might facilitate remote code execution.