SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 69990: SAS® Visual Analytics (on SAS® Viya® 3.x) includes a version of zlib that is susceptible to CVE-2022-37434

DetailsHotfixAboutRate It

Severity: High

Description: SAS Visual Analytics (on SAS Viya 3.x) for Microsoft Windows includes a version of zlib that is susceptible to CVE-2022-37434

Potential Impact: An attacker might execute arbitrary commands on the system, resulting in a denial of service or other exploits. 

Note: The SAS Viya 3.5 update for this issue is applicable only for Microsoft Windows environments. Customers running SAS Visual Analytics (on SAS Viya 3.x) for Linux should update the version of zlib in the operating system in order to address CVE-2022-37434.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual Analytics (on SAS Viya 3.x)Microsoft® Windows® for x648.5.1Viya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.