SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68417: Security updates for PostgreSQL ODBC drivers for SAS® Viya® 3.5

DetailsHotfixAboutRate It

Severity: Medium

Description: The following version of the PostgreSQL ODBC driver is used as the underlying technology for the SAS® Infrastructure Data Server in SAS Viya 3.5:

  • PostgreSQL 11.x (SAS Viya)
  • PostgreSQL 12.x (SPRE)

This version of the PostgreSQL ODBC driver has the following known security vulnerabilities:

Potential Impact:

  • Users that have UPDATE but not SELECT permission might still be able to obtain information from Write-only columns.
  • Users that have SELECT permission on only certain columns might still be able to gain information from all columns.

Updating the PostgreSQL ODBC driver from 11.x to 11.01 (SAS Viya) and PostgreSQL ODBC from 12.to 12.02 (SPRE) addresses all of these security concerns.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS ViyaMicrosoft® Windows® for x643.53.5ViyaViya
Microsoft Windows 8 Enterprise x643.53.5ViyaViya
Microsoft Windows 8 Pro x643.53.5ViyaViya
Microsoft Windows 8.1 Enterprise x643.53.5ViyaViya
Microsoft Windows 8.1 Pro x643.53.5ViyaViya
Microsoft Windows 103.53.5ViyaViya
Microsoft Windows Server 2003 for x643.53.5ViyaViya
Microsoft Windows Server 2008 R23.53.5ViyaViya
Microsoft Windows Server 2008 for x643.53.5ViyaViya
Microsoft Windows Server 2012 Datacenter3.53.5ViyaViya
Microsoft Windows Server 2012 R2 Datacenter3.53.5ViyaViya
Microsoft Windows Server 2012 R2 Std3.53.5ViyaViya
Microsoft Windows Server 2012 Std3.53.5ViyaViya
Microsoft Windows Server 20163.53.5ViyaViya
Microsoft Windows Server 20193.53.5ViyaViya
Windows 7 Enterprise x643.53.5ViyaViya
Windows 7 Home Premium x643.53.5ViyaViya
Windows 7 Professional x643.53.5ViyaViya
Windows 7 Ultimate x643.53.5ViyaViya
Windows Vista for x643.53.5ViyaViya
Linux for x643.53.5ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.