Problem Note 4509: SAS/SHARE secured server fails to honor host security file access
In Version 8 of SAS/SHARE Software, clients may find that they can
update SAS data sets through a secured SAS/SHARE server when the client
account lacks the appropriate file permissions to do so.
This problem exists only when ALL of the following conditions are true:
1. The server session is running with the TCPSEC=_SECURE_ and
AUTHENTICATE=REQUIRED options specified.
2. An initial client account with valid read and write permissions
has a SAS data set opened for update through the server.
3. While the valid read and write client has the data set open for
update, other client accounts (lacking proper file permissions)
can successfully open the same data set for update.
It should be noted that if the read and write client opens the data set
for input (read), subsequent access by others are properly controlled by
their respective file permissions and proper access is enforced.
A Technical Support hot fix for Release 8.1 TSLEVEL TS1M0 for this
issue is available at:
http://www.sas.com/techsup/download/hotfix/81_sbcs_prod_list.html#004509
A Technical Support hot fix for Release 8.2 TSLEVEL TS2M0 for this
issue is available at:
http://www.sas.com/techsup/download/hotfix/82_sbcs_prod_list.html#004509
For customers running SAS with Asian Language Support (DBCS), this
hot fix should be downloaded from:
http://www.sas.com/techsup/download/hotfix/82_dbcs_prod_list.html#004509
Operating System and Release Information
| SAS System | SAS/SHARE | Microsoft Windows NT Workstation | 8 TS M0 | 9 TS M0 |
| Microsoft Windows 2000 Server | 8 TS M0 | 9 TS M0 |
| Microsoft Windows 2000 Professional | 8 TS M0 | 9 TS M0 |
| Microsoft Windows 2000 Advanced Server | 8 TS M0 | 9 TS M0 |
| Microsoft Windows 2000 Datacenter Server | 8 TS M0 | 9 TS M0 |
| 64-bit Enabled Solaris | 8 TS M0 | |
| Solaris | 8 TS M0 | |
| OpenVMS VAX | 8 TS M0 | |
| IRIX | 8 TS M0 | |
| 64-bit Enabled HP-UX | 8 TS M0 | |
| ABI+ for Intel Architecture | 8 TS M0 | |
| HP-UX | 8 TS M0 | |
| CMS | 8 TS M0 | |
| 64-bit Enabled AIX | | 9 TS M0 |
| Tru64 UNIX | 8 TS M0 | 9 TS M0 |
| AIX | | 9 TS M0 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
| Type: | Problem Note |
| Priority: | alert |
| Date Modified: | 2002-04-25 14:56:13 |
| Date Created: | 2001-03-14 15:39:39 |