SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68158: The SAS® Web Server is affected by the vulnerability that is described in CVE-2020-13950

DetailsHotfixAboutRate It

Severity: High

Description: The version of Apache HTTP (2.4.46) that is provided by the SAS Web Server is affected by the vulnerability that is described in CVE-2020-13950.

Potential Impact: This vulnerability might enable an attacker to perform a Denial-of-Service attack.

Click the Hot Fix tab in this note to access the hot fix for this issue.

Note: The hot fix upgrades the Apache HTTP version to 2.4.48



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web ServerMicrosoft® Windows® for x649.469.4 TS1M7
64-bit Enabled AIX9.469.4 TS1M7
64-bit Enabled Solaris9.469.4 TS1M7
HP-UX IPF9.469.4 TS1M7
Linux for x649.469.4 TS1M7
Solaris for x649.469.4 TS1M7
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.