<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rapid 7 Vulnerabilities- Apache Tomcat in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerabilities-Apache-Tomcat/m-p/581230#M17006</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using SAS 9.4M6 on AIX servers. We found out several Tomcat Vulnerabilities on Rapid 7 report which referenced older tomcat versions in SAS Environment Manager and SAS Web App Server which are not currently being used by our servers ( I checked the start up logs to find the current versions of tomcat being used , which is 8.5 for the SAS Web App and 9.0 for Env Manager)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are the vulns listed with their respective locations referred in the report:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Directory disclosure (CVE-2015-5345)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Obsolete version&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Limited directory traversal (CVE-2015-5174)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Security Manager Bypass (CVE-2016-5018)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Information Disclosure (CVE-2017-5647)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Information Disclosure (CVE-2016-6816)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Security Manager Bypass (CVE-2016-6796)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Unrestricted Access to Global Resources (CVE-2016-6797)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: System Property Disclosure (CVE-2016-6794)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Timing Attack (CVE-2016-0762)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Security Manager bypass (CVE-2016-0706)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Moderate: Security Manager bypass (CVE-2016-0714)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Remote Code Execution (CVE-2016-8735)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Information Disclosure (CVE-2016-8745)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Remote Code Execution on Windows (CVE-2019-0232)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 7.0.55.A (/sas/install/SASHome/SASWebApplicationServer/9.4-1/9.4/tomcat-7.0.55.A.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I deleted the&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;sas/install/SASHome/SASWebApplicationServer/9.4-1 folder for the last vuln but I am not sure if the hotfix folder can be deleted? I checked our current installer report and found that the following bundled hot fix is installed:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 488px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/31750i3103788F7EF47C18/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;The link for that hotfix is : &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="csddf793561"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;A href="http://ftp.sas.com/techsup/download/hotfix/HF2/V/V77/V77014/xx/r64/V77014r6.html" target="_blank" rel="noopener"&gt;http://ftp.sas.com/techsup/download/hotfix/HF2/V/V77/V77014/xx/r64/V77014r6.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs2a6a52391"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This hotfix is now replaced by Hotfix : &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="csdc4a801"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;V77017&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="cs2a6a52391"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="csddf793561"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;A href="http://ftp.sas.com/techsup/download/hotfix/HF2/V77.html#V77014" target="_blank" rel="noopener"&gt;http://ftp.sas.com/techsup/download/hotfix/HF2/V77.html#V77014&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="csd69b18181"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;But, it is still listed for SAS Web Server 9.4_M3. We are currently using SAS 9.4_M6.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Can I remove the old hotfix folder ? Or have to install the new one?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;&amp;nbsp;Please suggest&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2019 17:56:16 GMT</pubDate>
    <dc:creator>Aasth</dc:creator>
    <dc:date>2019-08-14T17:56:16Z</dc:date>
    <item>
      <title>Rapid 7 Vulnerabilities- Apache Tomcat</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerabilities-Apache-Tomcat/m-p/581230#M17006</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using SAS 9.4M6 on AIX servers. We found out several Tomcat Vulnerabilities on Rapid 7 report which referenced older tomcat versions in SAS Environment Manager and SAS Web App Server which are not currently being used by our servers ( I checked the start up logs to find the current versions of tomcat being used , which is 8.5 for the SAS Web App and 9.0 for Env Manager)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are the vulns listed with their respective locations referred in the report:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Directory disclosure (CVE-2015-5345)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Obsolete version&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Limited directory traversal (CVE-2015-5174)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Security Manager Bypass (CVE-2016-5018)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Information Disclosure (CVE-2017-5647)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Information Disclosure (CVE-2016-6816)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Security Manager Bypass (CVE-2016-6796)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Unrestricted Access to Global Resources (CVE-2016-6797)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: System Property Disclosure (CVE-2016-6794)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Timing Attack (CVE-2016-0762)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Low: Security Manager bypass (CVE-2016-0706)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Moderate: Security Manager bypass (CVE-2016-0714)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Remote Code Execution (CVE-2016-8735)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Information Disclosure (CVE-2016-8745)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 6.0.44.B (/sas/install/SASHome/SASEnvironmentManager/2.5/hotfix/tomcat-6.0.44.B.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Apache Tomcat: Important: Remote Code Execution on Windows (CVE-2019-0232)&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN&gt;Vulnerable software installed: Apache Tomcat 7.0.55.A (/sas/install/SASHome/SASWebApplicationServer/9.4-1/9.4/tomcat-7.0.55.A.RELEASE/lib/catalina.jar)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I deleted the&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;sas/install/SASHome/SASWebApplicationServer/9.4-1 folder for the last vuln but I am not sure if the hotfix folder can be deleted? I checked our current installer report and found that the following bundled hot fix is installed:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 488px;"&gt;&lt;img src="https://communities.sas.com/t5/image/serverpage/image-id/31750i3103788F7EF47C18/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;The link for that hotfix is : &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="csddf793561"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;A href="http://ftp.sas.com/techsup/download/hotfix/HF2/V/V77/V77014/xx/r64/V77014r6.html" target="_blank" rel="noopener"&gt;http://ftp.sas.com/techsup/download/hotfix/HF2/V/V77/V77014/xx/r64/V77014r6.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs2a6a52391"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This hotfix is now replaced by Hotfix : &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="csdc4a801"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;V77017&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="cs2a6a52391"&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="csddf793561"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&lt;A href="http://ftp.sas.com/techsup/download/hotfix/HF2/V77.html#V77014" target="_blank" rel="noopener"&gt;http://ftp.sas.com/techsup/download/hotfix/HF2/V77.html#V77014&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="csd69b18181"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;But, it is still listed for SAS Web Server 9.4_M3. We are currently using SAS 9.4_M6.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="cs95e872d0"&gt;&lt;SPAN class="cs93c4bd381"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Can I remove the old hotfix folder ? Or have to install the new one?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;&amp;nbsp;Please suggest&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 17:56:16 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerabilities-Apache-Tomcat/m-p/581230#M17006</guid>
      <dc:creator>Aasth</dc:creator>
      <dc:date>2019-08-14T17:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid 7 Vulnerabilities- Apache Tomcat</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerabilities-Apache-Tomcat/m-p/581341#M17007</link>
      <description>Hi &lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/230568"&gt;@Aasth&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Have you checked the SAS Security Bulletin board for SAS 9.4 M6 Version? Here: &lt;A href="https://support.sas.com/en/security-bulletins.html" target="_blank"&gt;https://support.sas.com/en/security-bulletins.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Most of the CVEs listed by you are already taken care as part of SAS Security Update for 9.4 M6. You can find the list of vulnerabilities addressed in this link: &lt;A href="https://support.sas.com/en/security-bulletins/sas-security-update-for-sas-94m6.html#df3f745d-c882-4b54-bb90-ed727d5af5aa" target="_blank"&gt;https://support.sas.com/en/security-bulletins/sas-security-update-for-sas-94m6.html#df3f745d-c882-4b54-bb90-ed727d5af5aa&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It has also a hyperlink to the solution for these vulnerabilities. Here: &lt;A href="http://ftp.sas.com/techsup/download/hotfix/HF2/SAS_Security_Updates.html" target="_blank"&gt;http://ftp.sas.com/techsup/download/hotfix/HF2/SAS_Security_Updates.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Suggest you to apply those instead of deleting any binaries.&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Thu, 15 Aug 2019 04:04:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerabilities-Apache-Tomcat/m-p/581341#M17007</guid>
      <dc:creator>AnandVyas</dc:creator>
      <dc:date>2019-08-15T04:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid 7 Vulnerabilities- Apache Tomcat</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerabilities-Apache-Tomcat/m-p/581346#M17008</link>
      <description>&lt;P&gt;Some good advise by&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/52993"&gt;@AnandVyas&lt;/a&gt;&amp;nbsp;, thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/230568"&gt;@Aasth&lt;/a&gt;&amp;nbsp;, for questions like these, I would advise you to rather log a call with SAS Technical Support and resolve through that channel.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 05:13:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerabilities-Apache-Tomcat/m-p/581346#M17008</guid>
      <dc:creator>nhvdwalt</dc:creator>
      <dc:date>2019-08-15T05:13:43Z</dc:date>
    </item>
  </channel>
</rss>

