Problem Note 62945: SAS® Infrastructure Data Server update addresses known security vulnerabilities
Severity: High
Description: SAS® Infrastructure Data Server 9.4, which functions as a PostgreSQL database, is delivered with SAS® Viya® 3.4. The following security concerns related to PostgreSQL are present in this release of the SAS data server:
Potential Impact:
- Unprivileged users might be able to execute arbitrary code as the PostgreSQL service account.
- A flaw was discovered in PostgreSQL in which arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.
Updating the PostgreSQL server from 9.4 to 9.4.24 addresses all of these security concerns.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS Viya | Linux for x64 | 3.4 | 3.5 | | |
Microsoft® Windows® for x64 | 3.4 | 3.5 | | Viya |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Topic: | Data Management ==> Data Sources ==> External Databases ==> PostgreSQL
|
Date Modified: | 2019-06-27 10:09:18 |
Date Created: | 2018-09-18 12:18:43 |