SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70164: SAS® Lineage 3.3 contains a version of jackson-databind with known vulnerabilities

DetailsHotfixAboutRate It

Severity: Critical

Description: SAS® Lineage 3.3 contains a third-party Java library, jackson-databind 2.9.10, with the following known vulnerabilities:

Potential Impact: The potential impact varies. See the CVE records above for details.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS LineageMicrosoft® Windows® for x643.33.49.4 TS1M69.4 TS1M8
64-bit Enabled AIX3.33.49.4 TS1M69.4 TS1M8
64-bit Enabled Solaris3.33.49.4 TS1M69.4 TS1M8
HP-UX IPF3.33.49.4 TS1M69.4 TS1M8
Linux for x643.33.49.4 TS1M69.4 TS1M8
Solaris for x643.33.49.4 TS1M69.4 TS1M8
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.