SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 64442: Apache HTTP Server vulnerabilities and OpenSSL vulnerabilities exist in SAS® Web Server 9.45

DetailsHotfixAboutRate It

Severity: High

Description: SAS Web Server 9.45, which is delivered with SAS® 9.4M6 (TS1M6), includes Apache HTTP Server 2.4.34 and OpenSSL 1.0.2o. Apache HTTP Server 2.4.34 contains vulnerabilities that are described on the Apache HTTP Server Project website. OpenSSL 1.0.2o contains vulnerabilities as described on the OpenSSL website.

Note: SAS Web Server 9.45 is part of the SAS® 9.4 Integration Technologies middle tier. The web server is included with SAS® BI Server, SAS® Enterprise BI Server, SAS® Visual Analytics, and any SAS® solution that includes a middle tier.

Potential Impact: The server might be vulnerable to a variety of attacks.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web ServerMicrosoft® Windows® for x649.459.4 TS1M6
64-bit Enabled AIX9.459.4 TS1M6
64-bit Enabled Solaris9.459.4 TS1M6
HP-UX IPF9.459.4 TS1M6
Linux for x649.459.4 TS1M6
Solaris for x649.459.4 TS1M6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.