SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 62945: SAS® Infrastructure Data Server update addresses known security vulnerabilities

DetailsHotfixAboutRate It

Severity: High

Description: SAS® Infrastructure Data Server 9.4, which functions as a PostgreSQL database, is delivered with SAS® Viya® 3.4. The following security concerns related to PostgreSQL are present in this release of the SAS data server: 

Potential Impact:

  • Unprivileged users might be able to execute arbitrary code as the PostgreSQL service account.
  • A flaw was discovered in PostgreSQL in which arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.

Updating the PostgreSQL server from 9.4 to 9.4.24 addresses all of these security concerns.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS ViyaLinux for x643.43.5
Microsoft® Windows® for x643.43.5Viya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.