SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 56385: OpenSSL security vulnerabilities (11 Jun 2015 and 9 Jul 2015) exist in the Secure Sockets Layer (SSL) capability in SAS® Foundation products

DetailsHotfixAboutRate It

For SAS® 9.3, SAS® 9.4 TS1M0, and SAS 9.4 TS1M1 in UNIX and z/OS operating environments, the SSL capability in SAS Foundation products includes OpenSSL 0.9.8, which contains security vulnerabilities. For SAS 9.4 TS1M2 under UNIX and z/OS, the SSL capability in SAS Foundation products includes OpenSSL 1.0.1h, which contains the same vulnerabilities. For SAS 9.4 TS1M3 under UNIX and z/OS, the SSL capability in SAS Foundation products includes OpenSSL 1.0.1m, which contains the same vulnerabilities. These vulnerabilities are described in the OpenSSL Security Advisory (11 Jun 2015) and the OpenSSL Security Advisory (9 Jul 2015).

Click the Hot Fix tab in this note to access the hot fix for this issue.

The hot fixes for SAS 9.3, SAS 9.4 TS1M0, and SAS 9.4 TS1M1 upgrade OpenSSL to version 0.9.8zg. The hot fix for SAS 9.4 TS1M2 and SAS 9.4 TS1M3 upgrade OpenSSL to version 1.0.1p.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemBase SASz/OS9.3_M29.3 TS1M2
Z649.3_M29.3 TS1M2
64-bit Enabled AIX9.3_M29.3 TS1M2
64-bit Enabled HP-UX9.3_M29.3 TS1M2
64-bit Enabled Solaris9.3_M29.3 TS1M2
HP-UX IPF9.3_M29.3 TS1M2
Linux9.3_M29.3 TS1M2
Linux for x649.3_M29.3 TS1M2
Solaris for x649.3_M29.3 TS1M2
SAS SystemSAS/CONNECTz/OS9.3_M29.3 TS1M2
Z649.3_M29.3 TS1M2
64-bit Enabled AIX9.3_M29.3 TS1M2
64-bit Enabled HP-UX9.3_M29.3 TS1M2
64-bit Enabled Solaris9.3_M29.3 TS1M2
HP-UX IPF9.3_M29.3 TS1M2
Linux9.3_M29.3 TS1M2
Linux for x649.3_M29.3 TS1M2
Solaris for x649.3_M29.3 TS1M2
SAS SystemSAS/SHAREz/OS9.3_M19.3 TS1M2
64-bit Enabled AIX9.3_M19.3 TS1M2
64-bit Enabled HP-UX9.3_M19.3 TS1M2
64-bit Enabled Solaris9.3_M19.3 TS1M2
HP-UX IPF9.3_M19.3 TS1M2
Linux9.3_M19.3 TS1M2
Linux for x649.3_M19.3 TS1M2
Solaris for x649.3_M19.3 TS1M2
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.