SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 68992: SAS® Event Stream Processing contains a Log4J 1.x library with known vulnerabilities

DetailsHotfixAboutRate It

Severity: Informational

Description: SAS Event Stream Processing ships a Log4j 1.x library at /opt/sas/viya/home/SASEventStreamProcessingEngine/6.2/lib/log4j-1.2.17.jar. The following CVEs exist for Log4j 1.x:

Potential Impact: As described in the Log4j v1 security bulletin, SAS Event Stream Processing is not impacted by these vulnerabilities. But, the Log4j v1 library might be flagged by security scanners.

Note: Users of SAS Event Stream Processing 6.1 or earlier should contact SAS Technical Support for additional instructions. 

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Event Stream Processing for Edge ComputingLinux for x646.2Viya
Linux for AArch646.2Viya
SAS SystemSAS Event Stream Processing EngineLinux for x646.2
Microsoft® Windows® for x646.2
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.