SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 61700: OpenSSL vulnerabilities exist in the Secure Sockets Layer (SSL) capability in SAS® Foundation products (OpenSSL advisories through 02 November 2017)

DetailsHotfixAboutRate It

Severity: Medium

Description: For SAS® 9.3 and SAS® 9.4 in the z/OS and UNIX operating environments, the SSL capability in SAS® Foundation products includes OpenSSL 1.0.2j, which contains security vulnerabilities. The vulnerabilities are described here: OpenSSL Security Advisory (02 Nov 2017)

Potential Impact: Under certain conditions, someone might be able to decrypt data.

Click the Hot Fix tab in this note to access the hot fix for this issue.

OpenSSL version 1.0.2n corrects the problem, and this version is available in the hot fix.



Operating System and Release Information

Product FamilyProductSystemSAS Release
ReportedFixed*
SAS SystemSAS FoundationSolaris for x649.3 TS1M0
Linux9.3 TS1M0
Linux for x649.3 TS1M0
HP-UX IPF9.3 TS1M0
64-bit Enabled Solaris9.3 TS1M0
64-bit Enabled HP-UX9.3 TS1M0
64-bit Enabled AIX9.3 TS1M0
z/OS 64-bit9.3 TS1M0
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.