SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68699: DataFlux® Data Management Studio and DataFlux® Data Management Server 2.9 contain an Apache Log4j component with known vulnerabilities

DetailsHotfixAboutRate It

Severity: Critical

Description: DataFlux Data Management Studio and DataFlux Data Management Server 2.9 contain an Apache Log4J version 2 component that is affected by the following known vulnerabilities: 

Potential Impact: Refer to the CVE records listed in the previous section for details. Impacts vary and include the potential for remote code execution by an attacker.

Important:

  • The information in this SAS Note helps you implement the guidance that is provided in the SAS Security Bulletin that is entitled SAS Statement Regarding Remote Code Execution Vulnerability (CVE-2021-44228)
  • Before you apply the hot fixes supplied by this SAS Note, review the guidance in that SAS Security Bulletin and also complete all instructions for the applicable platform in Instructions for the SAS® Response to Log4j Vulnerabilities.
  • The hot fixes supplied in this SAS Note provide product-specific mitigation for DataFlux only.
  • The new hot fixes J6K009 and J6J006 that are supplied in this SAS Note replace the initial hot fixes J6K007 and J6J004. 
  • The new hot fixes J6K009 and J6J006 ​​​​upgrade the affected Log4j libraries that are included with SAS Data Management Server and SAS Data Management Studio to 2.17.1 and provide mitigation for all of the vulnerabilities listed above.
  • The initial hot fixes J6K007 and J6J004 upgrade the Log4j libraries that are included with SAS Data Management Server and SAS Data Management Studio to 2.17 and provide mitigation for CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105 only.
  • The new hot fixes J6K009 and J6J006 do not require the initial hot fixes J6K007 and J6J004 to be installed first.  If the initial hot fixes have already been installed, the new hot fixes can be installed afterward.   
  • If necessary, this SAS Note will be updated as additional information becomes available. 

History:

Note: For each update listed in the History section, new or updated text is marked and is rendered in a darker color. The marks indicate changes from only the immediately preceding version of the SAS Note.

  • 1-24-2022 -  Updated list of known vulnerabilities to include CVE-2021-44832; released new hot fixes J6K009 and J6J006 that replace initial hot fixes.
  • 12-22-2021 - SAS Note providing initial hot fixes J6K007 and J6J004 for known vulnerabilities CVE-2021-44228, CVE-2021-45046, and CVE-2021-45105 published.

 

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
DatafluxDataFlux Data Management StudioMicrosoft® Windows® for x642.9
Microsoft Windows 8 Enterprise 32-bit2.9
Microsoft Windows 8 Enterprise x642.9
Microsoft Windows 8 Pro 32-bit2.9
Microsoft Windows 8 Pro x642.9
Microsoft Windows 8.1 Enterprise 32-bit2.9
Microsoft Windows 8.1 Enterprise x642.9
Microsoft Windows 8.1 Pro 32-bit2.9
Microsoft Windows 8.1 Pro x642.9
Microsoft Windows 102.9
Microsoft Windows 112.9
Microsoft Windows 95/982.9
Microsoft Windows 2000 Advanced Server2.9
Microsoft Windows 2000 Datacenter Server2.9
Microsoft Windows 2000 Server2.9
Microsoft Windows 2000 Professional2.9
Microsoft Windows NT Workstation2.9
Microsoft Windows Server 2003 Datacenter Edition2.9
Microsoft Windows Server 2003 Enterprise Edition2.9
Microsoft Windows Server 2003 Standard Edition2.9
Microsoft Windows Server 2003 for x642.9
Microsoft Windows Server 20082.9
Microsoft Windows Server 2008 R22.9
Microsoft Windows Server 2008 for x642.9
Microsoft Windows Server 2012 Datacenter2.9
Microsoft Windows Server 2012 R2 Datacenter2.9
Microsoft Windows Server 2012 R2 Std2.9
Microsoft Windows Server 2012 Std2.9
Microsoft Windows Server 20162.9
Microsoft Windows Server 20192.9
Microsoft Windows Server 20222.9
Microsoft Windows XP Professional2.9
Windows 7 Enterprise 32 bit2.9
Windows 7 Enterprise x642.9
Windows 7 Home Premium 32 bit2.9
Windows 7 Home Premium x642.9
Windows 7 Professional 32 bit2.9
Windows 7 Professional x642.9
Windows 7 Ultimate 32 bit2.9
Windows 7 Ultimate x642.9
Windows Millennium Edition (Me)2.9
Windows Vista2.9
Windows Vista for x642.9
DatafluxDataFlux Data Management ServerMicrosoft® Windows® for x642.9
Microsoft Windows 8 Enterprise 32-bit2.9
Microsoft Windows 8 Enterprise x642.9
Microsoft Windows 8 Pro 32-bit2.9
Microsoft Windows 8 Pro x642.9
Microsoft Windows 8.1 Enterprise 32-bit2.9
Microsoft Windows 8.1 Enterprise x642.9
Microsoft Windows 8.1 Pro 32-bit2.9
Microsoft Windows 8.1 Pro x642.9
Microsoft Windows 102.9
Microsoft Windows 112.9
Microsoft Windows 95/982.9
Microsoft Windows 2000 Advanced Server2.9
Microsoft Windows 2000 Datacenter Server2.9
Microsoft Windows 2000 Server2.9
Microsoft Windows 2000 Professional2.9
Microsoft Windows NT Workstation2.9
Microsoft Windows Server 2003 Datacenter Edition2.9
Microsoft Windows Server 2003 Enterprise Edition2.9
Microsoft Windows Server 2003 Standard Edition2.9
Microsoft Windows Server 2003 for x642.9
Microsoft Windows Server 20082.9
Microsoft Windows Server 2008 R22.9
Microsoft Windows Server 2008 for x642.9
Microsoft Windows Server 2012 Datacenter2.9
Microsoft Windows Server 2012 R2 Datacenter2.9
Microsoft Windows Server 2012 R2 Std2.9
Microsoft Windows Server 2012 Std2.9
Microsoft Windows Server 20162.9
Microsoft Windows Server 20192.9
Microsoft Windows Server 20222.9
Microsoft Windows XP Professional2.9
Windows 7 Enterprise 32 bit2.9
Windows 7 Enterprise x642.9
Windows 7 Home Premium 32 bit2.9
Windows 7 Home Premium x642.9
Windows 7 Professional 32 bit2.9
Windows 7 Professional x642.9
Windows 7 Ultimate 32 bit2.9
Windows 7 Ultimate x642.9
Windows Millennium Edition (Me)2.9
Windows Vista2.9
Windows Vista for x642.9
64-bit Enabled AIX2.9
64-bit Enabled Solaris2.9
HP-UX IPF2.9
Linux for x642.9
Solaris for x642.9
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.