SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 59244: OpenSSL vulnerabilities exist in the Secure Sockets Layer (SSL) capability in SAS® Foundation products (OpenSSL advisories through 26 September 2016)

DetailsHotfixAboutRate It

For SAS 9.3 and SAS 9.4 in UNIX and z/OS operating environments, the SSL capability in SAS® Foundation products includes OpenSSL 1.0.2h and 1.0.2i, which contain security vulnerabilities.

The vulnerabilities are described here:

OpenSSL version 1.0.2j corrects the problem and is available via a hot fix.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemBase SAS64-bit Enabled Solaris9.39.4_M49.3 TS1M09.4 TS1M4
HP-UX IPF9.39.4_M49.3 TS1M09.4 TS1M4
Linux9.39.4_M49.3 TS1M09.4 TS1M4
Linux for x649.39.4_M49.3 TS1M09.4 TS1M4
64-bit Enabled HP-UX9.39.4_M49.3 TS1M09.4 TS1M4
64-bit Enabled AIX9.39.4_M49.3 TS1M09.4 TS1M4
z/OS 64-bit9.39.4_M49.3 TS1M09.4 TS1M4
z/OS9.39.4_M49.3 TS1M09.4 TS1M4
Solaris for x649.39.4_M49.3 TS1M09.4 TS1M4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.