Problem Note 57686: OpenSSL security vulnerabilities (4 Dec 2015) exist in the Secure Sockets Layer (SSL) capability in SASĀ® Foundation products
For SAS® 9.3, SAS® 9.4 TS1M0, and SAS 9.4 TS1M1 in UNIX and z/OS operating environments, the SSL capability in SAS Foundation products includes OpenSSL 0.9.8, which contains security vulnerabilities. For SAS 9.4 TS1M2 under UNIX and z/OS, the SSL capability in SAS Foundation products includes OpenSSL 1.0.1h, which contains the same vulnerabilities. For SAS 9.4 TS1M3 under UNIX and z/OS, the SSL capability in SAS Foundation products includes OpenSSL 1.0.1m, which contains the same vulnerabilities. These vulnerabilities are described in the
OpenSSL Security Advisory (4 Dec 2015).
Click the Hot Fix tab in this note to access the hot fix for this issue.
The hot fixes for SAS 9.3 TS1M0, SAS 9.4 TS1M0, and SAS 9.4 TS1M1 upgrade OpenSSL to version 0.9.8zh. The hot fix for SAS 9.4 TS1M2 and SAS 9.4 TS1M3 upgrade OpenSSL to version 1.0.1r.
Operating System and Release Information
SAS System | SAS/SHARE | Solaris for x64 | 9.3_M1 | | 9.3 TS1M2 | |
Linux for x64 | 9.3_M1 | | 9.3 TS1M2 | |
Linux | 9.3_M1 | | 9.3 TS1M2 | |
HP-UX IPF | 9.3_M1 | | 9.3 TS1M2 | |
64-bit Enabled Solaris | 9.3_M1 | | 9.3 TS1M2 | |
64-bit Enabled HP-UX | 9.3_M1 | | 9.3 TS1M2 | |
64-bit Enabled AIX | 9.3_M1 | | 9.3 TS1M2 | |
z/OS | 9.3_M1 | | 9.3 TS1M2 | |
SAS System | SAS/CONNECT | Solaris for x64 | 9.3_M2 | | 9.3 TS1M2 | |
Linux for x64 | 9.3_M2 | | 9.3 TS1M2 | |
Linux | 9.3_M2 | | 9.3 TS1M2 | |
HP-UX IPF | 9.3_M2 | | 9.3 TS1M2 | |
64-bit Enabled Solaris | 9.3_M2 | | 9.3 TS1M2 | |
64-bit Enabled HP-UX | 9.3_M2 | | 9.3 TS1M2 | |
64-bit Enabled AIX | 9.3_M2 | | 9.3 TS1M2 | |
z/OS 64-bit | 9.3_M2 | | 9.3 TS1M2 | |
z/OS | 9.3_M2 | | 9.3 TS1M2 | |
SAS System | Base SAS | Solaris for x64 | 9.3_M2 | | 9.3 TS1M2 | |
Linux for x64 | 9.3_M2 | | 9.3 TS1M2 | |
Linux | 9.3_M2 | | 9.3 TS1M2 | |
HP-UX IPF | 9.3_M2 | | 9.3 TS1M2 | |
64-bit Enabled Solaris | 9.3_M2 | | 9.3 TS1M2 | |
64-bit Enabled HP-UX | 9.3_M2 | | 9.3 TS1M2 | |
64-bit Enabled AIX | 9.3_M2 | | 9.3 TS1M2 | |
z/OS 64-bit | 9.3_M2 | | 9.3 TS1M2 | |
z/OS | 9.3_M2 | | 9.3 TS1M2 | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2016-02-22 14:53:44 |
Date Created: | 2016-02-18 14:56:51 |