Problem Note 70224: SAS® Federation Server 4.5 uses a version of ODBC drivers with known vulnerabilities
Severity: High
Description: SAS Federation Server 4.5 contains a version of libcurl, which contains the following known vulnerabilities, in the DataDirect ODBC drivers.
Potential Impact: Refer to the CVE records listed above for details.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
| SAS System | SAS Federation Server | Microsoft® Windows® for x64 | 4.5 | 4.5 | 9.4 TS1M8 | 9.4 TS1M8 |
| 64-bit Enabled AIX | 4.5 | 4.5 | 9.4 TS1M8 | 9.4 TS1M8 |
| Linux for x64 | 4.5 | 4.5 | 9.4 TS1M8 | 9.4 TS1M8 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
| Type: | Problem Note |
| Priority: | high |
| Date Modified: | 2023-07-03 13:30:41 |
| Date Created: | 2023-06-30 15:01:58 |