By Carrie Foreman, Managed Services Manager
A newly identified security flaw in 3rd party components used by SAS Viya exposes systems to potential compromise through PDF processing. This vulnerability, tracked as CVE-2025-66516, poses a significant risk to data integrity and compliance if left unpatched.
What’s the issue?
A critical vulnerability—CVE-2025-66516—has been discovered in SAS Viya Stable 2025.08 and LTS 2025.03. This flaw is tied to the Apache Tika XXE (XML External Entity) issue and is rated CVSS 10.0, the highest possible severity.
Who is at risk?
Potential impact
What should you do?
Need a hand?
If you need assistance checking your SAS Viya version, expert guidance on upgrading or patching, or a thorough security review of your platform, contact Katalyze Data immediately. Our team specializes in securing and maintaining SAS environments, and we are ready to help you resolve this vulnerability and ensure your systems remain protected.
Don’t wait—reach out to Katalyze Data now for prompt support and peace of mind.