Problem Note 69990: SAS® Visual Analytics (on SAS® Viya® 3.x) includes a version of zlib that is susceptible to CVE-2022-37434
Severity: High
Description: SAS Visual Analytics (on SAS Viya 3.x) for Microsoft Windows includes a version of zlib that is susceptible to CVE-2022-37434.
Potential Impact: An attacker might execute arbitrary commands on the system, resulting in a denial of service or other exploits.
Note: The SAS Viya 3.5 update for this issue is applicable only for Microsoft Windows environments. Customers running SAS Visual Analytics (on SAS Viya 3.x) for Linux should update the version of zlib in the operating system in order to address CVE-2022-37434.
Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.
Operating System and Release Information
SAS System | SAS Visual Analytics (on SAS Viya 3.x) | Microsoft® Windows® for x64 | 8.5.1 | | Viya | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2023-04-01 11:28:51 |
Date Created: | 2023-03-31 14:23:06 |