SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70671: SAS® Viya® 3.5 contains a vulnerable version of Apache Xerces2 Java Parser

DetailsHotfixAboutRate It

Severity: High

Description: SAS Viya 3.5 contains a version of Apache Xerces2 Java Parser earlier than 2.12.0, which is vulnerable to CVE-2012-0881.

Potential Impact: SAS applications might be susceptible to denial of service attacks.

Click the Hot Fix tab in this note to access the hot fix for this issue.

 



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Viya 3.xLinux for x643.53.5Viya 3.5Viya 3.5
Microsoft® Windows® for x643.5Viya 3.5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.