SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 54374: Secure Sockets Layer (SSL) capability in SAS® Foundation products is susceptible to the POODLE security vulnerability

DetailsHotfixAboutRate It

The Secure Sockets Layer (SSL) capability in SAS Foundation products supports SSL 3.0. As a result, it is susceptible to the POODLE vulnerability that is described in the following documents:

The SSL capability can be used in SAS Foundation products in a variety of ways, for example:

  • a SAS/CONNECT® spawner configured for SSL or its successor, Transport Layer Security (TLS)
  • a SAS/SHARE® server configured for SSL or TLS
  • a LIBNAME URL or a LIBNAME WebDAV statement that specifies an HTTPS URL
  • an HTTP procedure or SOAP procedure step that specifies an HTTPS URL
  • a SAS® Metadata Server that is configured for direct use of Lightweight Directory Access Protocol (LDAP) authentication using SSL or TLS

Please contact SAS Technical Support to obtain the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemBase SASOpenVMS on HP Integrity9.219.4_M39.2 TS2M09.4 TS1M3
Linux for x649.219.4_M39.2 TS2M09.4 TS1M3
Linux9.219.4_M39.2 TS2M09.4 TS1M3
HP-UX IPF9.219.4_M39.2 TS2M09.4 TS1M3
64-bit Enabled Solaris9.219.4_M39.2 TS2M09.4 TS1M3
64-bit Enabled HP-UX9.219.4_M39.2 TS2M09.4 TS1M3
64-bit Enabled AIX9.219.4_M39.2 TS2M09.4 TS1M3
Windows Vista for x649.219.2 TS2M0
Windows Vista9.219.2 TS2M0
Microsoft Windows XP Professional9.219.2 TS2M0
Microsoft Windows Server 2008 for x649.219.4_M39.2 TS2M09.4 TS1M3
Microsoft Windows Server 2008 R29.219.4_M39.2 TS2M09.4 TS1M3
Microsoft Windows Server 2003 for x649.219.2 TS2M0
Microsoft Windows Server 2003 Standard Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Enterprise Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Datacenter Edition9.219.2 TS2M0
Microsoft® Windows® for x649.219.4_M39.2 TS2M09.4 TS1M3
Microsoft Windows XP 64-bit Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Enterprise 64-bit Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Datacenter 64-bit Edition9.219.2 TS2M0
Microsoft® Windows® for 64-Bit Itanium-based Systems9.219.2 TS2M0
z/OS9.219.4_M39.2 TS2M09.4 TS1M3
Solaris for x649.219.4_M39.2 TS2M09.4 TS1M3
SAS SystemSAS/CONNECTz/OS9.219.4_M39.2 TS2M09.4 TS1M3
Microsoft® Windows® for 64-Bit Itanium-based Systems9.219.2 TS2M0
Microsoft Windows Server 2003 Datacenter 64-bit Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Enterprise 64-bit Edition9.219.2 TS2M0
Microsoft Windows XP 64-bit Edition9.219.2 TS2M0
Microsoft® Windows® for x649.219.4_M39.2 TS2M09.4 TS1M3
Microsoft Windows Server 2003 Datacenter Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Enterprise Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Standard Edition9.219.2 TS2M0
Microsoft Windows Server 2003 for x649.219.2 TS2M0
Microsoft Windows Server 2008 R29.219.4_M39.2 TS2M09.4 TS1M3
Microsoft Windows Server 2008 for x649.219.4_M39.2 TS2M09.4 TS1M3
Microsoft Windows XP Professional9.219.2 TS2M0
Windows Vista9.219.2 TS2M0
Windows Vista for x649.219.2 TS2M0
64-bit Enabled AIX9.219.4_M39.2 TS2M09.4 TS1M3
64-bit Enabled HP-UX9.219.4_M39.2 TS2M09.4 TS1M3
64-bit Enabled Solaris9.219.4_M39.2 TS2M09.4 TS1M3
HP-UX IPF9.219.4_M39.2 TS2M09.4 TS1M3
Linux9.219.4_M39.2 TS2M09.4 TS1M3
Linux for x649.219.4_M39.2 TS2M09.4 TS1M3
OpenVMS on HP Integrity9.219.4_M39.2 TS2M09.4 TS1M3
Solaris for x649.219.4_M39.2 TS2M09.4 TS1M3
SAS SystemSAS/SHAREz/OS9.219.4_M29.2 TS2M09.4 TS1M3
Microsoft® Windows® for 64-Bit Itanium-based Systems9.219.2 TS2M0
Microsoft Windows Server 2003 Datacenter 64-bit Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Enterprise 64-bit Edition9.219.2 TS2M0
Microsoft Windows XP 64-bit Edition9.219.2 TS2M0
Microsoft® Windows® for x649.219.4_M29.2 TS2M09.4 TS1M3
Microsoft Windows Server 2003 Datacenter Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Enterprise Edition9.219.2 TS2M0
Microsoft Windows Server 2003 Standard Edition9.219.2 TS2M0
Microsoft Windows Server 2003 for x649.219.2 TS2M0
Microsoft Windows Server 2008 R29.219.4_M29.2 TS2M09.4 TS1M3
Microsoft Windows Server 2008 for x649.219.4_M29.2 TS2M09.4 TS1M3
Microsoft Windows XP Professional9.219.2 TS2M0
Windows Vista9.219.2 TS2M0
Windows Vista for x649.219.2 TS2M0
64-bit Enabled AIX9.219.4_M29.2 TS2M09.4 TS1M3
64-bit Enabled HP-UX9.219.4_M29.2 TS2M09.4 TS1M3
64-bit Enabled Solaris9.219.4_M29.2 TS2M09.4 TS1M3
HP-UX IPF9.219.4_M29.2 TS2M09.4 TS1M3
Linux9.219.4_M29.2 TS2M09.4 TS1M3
Linux for x649.219.4_M29.2 TS2M09.4 TS1M3
OpenVMS on HP Integrity9.219.4_M29.2 TS2M09.4 TS1M3
Solaris for x649.219.4_M29.2 TS2M09.4 TS1M3
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.