![]() | ![]() | ![]() | ![]() | ![]() |
For SAS 9.3 and SAS 9.4 in UNIX and z/OS operating environments, the SSL capability in SAS Foundation products includes OpenSSL 1.0.1, which contains security vulnerabilities. These vulnerabilities are described in the OpenSSL Security Advisory (3rd May 2016).
OpenSSL version 1.0.2h corrects the problem, and is available via a hot fix.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | Base SAS | z/OS | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 |
z/OS 64-bit | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 | ||
64-bit Enabled AIX | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 | ||
64-bit Enabled HP-UX | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 | ||
64-bit Enabled Solaris | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 | ||
Linux | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 | ||
Linux for x64 | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 | ||
Solaris for x64 | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 | ||
HP-UX IPF | 9.3 | 9.4_M3 | 9.3 TS1M0 | 9.4 TS1M3 |