SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68891: A Log4j version 1.2 vulnerability (when using JMSAppender) is identified in SAS® Anti-Money Laundering

DetailsHotfixAboutRate It

Severity: High

Description: SAS Anti-Money Laundering contains Log4jv1.2 security vulnerabilities when JMSAppender is configured. For more information, see CVE-2021-4104

Potential Impact: An attacker might use JMSAppender to perform a Java Naming and Directory Interface (JNDI) request that causes remote code execution.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Anti-Money LaunderingMicrosoft® Windows® for x647.1
64-bit Enabled AIX7.1
64-bit Enabled Solaris7.1
Linux for x647.1
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.