SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 69029: SAS® Environment Manager 2.5 contains a Terracotta Quartz Scheduler library affected by CVE-2019-13990

DetailsHotfixAboutRate It

Severity: High

Description: SAS Environment Manager 2.5 contains Terracotta Quartz Scheduler, which is affected by the vulnerability described in CVE-2019-13990.

Potential Impact: The SAS Environment Manager might allow XXE attacks. Refer to CVE-2019-13990 for details.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Environment ManagerMicrosoft® Windows® for x642.5_M42.5_M59.4 TS1M79.4 TS1M8
64-bit Enabled AIX2.5_M42.5_M59.4 TS1M79.4 TS1M8
64-bit Enabled Solaris2.5_M42.5_M59.4 TS1M79.4 TS1M8
HP-UX IPF2.5_M42.5_M59.4 TS1M79.4 TS1M8
Linux for x642.5_M42.5_M59.4 TS1M79.4 TS1M8
Solaris for x642.5_M42.5_M59.4 TS1M79.4 TS1M8
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.