Problem Note 68597: The SAS® Risk Governance Framework contains an Apache Log4j component with known vulnerabilities
Severity: Critical
Description: The Apache Log4j Java logging library that is included with the SAS Risk Governance Framework is affected by the vulnerabilities that are described in the following CVE records:
Potential Impact: These vulnerabilities can have varied impacts, including the potential to enable a remote unauthenticated attacker to control log messages or log message parameters. An attacker could execute arbitrary code loaded from LDAP servers and take complete control of the system. For details, see the CVE records above.
Important: Before you apply the hot fix that is associated with this note, perform the following steps:
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS Risk Governance Framework | Microsoft Windows 8 Pro x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 8.1 Enterprise 32-bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 8.1 Enterprise x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 8.1 Pro 32-bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 8.1 Pro x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 10 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2008 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2008 R2 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2008 for x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2012 Datacenter | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2012 R2 Datacenter | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2012 R2 Std | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2012 Std | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows Server 2016 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Enterprise 32 bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Enterprise x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Home Premium 32 bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Home Premium x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Professional 32 bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Professional x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Ultimate 32 bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Windows 7 Ultimate x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Linux for x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 8 Pro 32-bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 8 Enterprise x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft Windows 8 Enterprise 32-bit | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
Microsoft® Windows® for x64 | 7.4 | 7.5 | 9.4 TS1M5 | 9.4 TS1M8 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | alert |
Date Modified: | 2023-02-14 16:07:42 |
Date Created: | 2021-11-12 08:58:12 |