SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68493: DataFlux® Data Management Server 2.9 contains an Apache Velocity component with a known vulnerability

DetailsHotfixAboutRate It

Severity: High

Description: The Apache Velocity component included with DataFlux Data Management Server 2.9 is affected by the vulnerability described in the following CVE record:

Potential Impact: This vulnerability might enable an attacker to execute arbitrary Java code or run arbitrary system commands. For details, see the CVE report above.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
DatafluxDataFlux Data Management ServerMicrosoft® Windows® for x642.9
Microsoft Windows 8 Enterprise 32-bit2.9
Microsoft Windows 8 Enterprise x642.9
Microsoft Windows 8 Pro 32-bit2.9
Microsoft Windows 8 Pro x642.9
Microsoft Windows 8.1 Enterprise 32-bit2.9
Microsoft Windows 8.1 Enterprise x642.9
Microsoft Windows 8.1 Pro 32-bit2.9
Microsoft Windows 8.1 Pro x642.9
Microsoft Windows 102.9
Microsoft Windows 95/982.9
Microsoft Windows 2000 Advanced Server2.9
Microsoft Windows 2000 Datacenter Server2.9
Microsoft Windows 2000 Server2.9
Microsoft Windows 2000 Professional2.9
Microsoft Windows NT Workstation2.9
Microsoft Windows Server 2003 Datacenter Edition2.9
Microsoft Windows Server 2003 Enterprise Edition2.9
Microsoft Windows Server 2003 Standard Edition2.9
Microsoft Windows Server 2003 for x642.9
Microsoft Windows Server 20082.9
Microsoft Windows Server 2008 R22.9
Microsoft Windows Server 2008 for x642.9
Microsoft Windows Server 2012 Datacenter2.9
Microsoft Windows Server 2012 R2 Datacenter2.9
Microsoft Windows Server 2012 R2 Std2.9
Microsoft Windows Server 2012 Std2.9
Microsoft Windows Server 20162.9
Microsoft Windows Server 20192.9
Microsoft Windows XP Professional2.9
Windows 7 Enterprise 32 bit2.9
Windows 7 Enterprise x642.9
Windows 7 Home Premium 32 bit2.9
Windows 7 Home Premium x642.9
Windows 7 Professional 32 bit2.9
Windows 7 Professional x642.9
Windows 7 Ultimate 32 bit2.9
Windows 7 Ultimate x642.9
Windows Millennium Edition (Me)2.9
Windows Vista2.9
Windows Vista for x642.9
64-bit Enabled AIX2.9
64-bit Enabled Solaris2.9
HP-UX IPF2.9
Linux for x642.9
Solaris for x642.9
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.