SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 64003: OpenSSL vulnerabilities exist in the Secure Sockets Layer (SSL) capability in SAS® Foundation products (OpenSSL advisories through 26 February 2019)

DetailsHotfixAboutRate It

Severity: Medium

Description: For SAS® 9.3 and SAS® 9.4 in the z/OS and UNIX operating environments, the SSL capability in SAS® Foundation products includes OpenSSL 1.0.2n. This version of OpenSSL contains security vulnerabilities per a February 26, 2019 advisory on the OpenSSL website.

Potential Impact: Under certain conditions, someone might be able to decrypt data.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemSAS Release
ReportedFixed*
SAS SystemSAS Foundationz/OS 64-bit9.3 TS1M0
64-bit Enabled AIX9.3 TS1M0
64-bit Enabled HP-UX9.3 TS1M0
64-bit Enabled Solaris9.3 TS1M0
HP-UX IPF9.3 TS1M0
Linux9.3 TS1M0
Linux for x649.3 TS1M0
Solaris for x649.3 TS1M0
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.