When you run automated vulnerability scanners in your SAS 9.4 environments, outdated versions of Apache HTTP Server (httpd), OpenSSL, or Apache Tomcat are sometimes identified.
To determine the appropriate hot fix to update the identified component, you must complete the following steps:
| Hot Fix | Apache httpd Version | OpenSSL Version |
|---|---|---|
| Upgrading Your SAS Viya Software | 2.4.57 | 1.0.2zh |
| SAS® 9.4 Maintenance Release | Product Release | Current Hot Fix | Apache httpd Version | OpenSSL Version |
|---|---|---|---|---|
| M9 | 9.52 | R1C002 | 2.4.66 | 3.5.5 |
| M8 | 9.47 | M1V008 | 2.4.66 | 3.5.5 |
| M7 | 9.46 | J8M013 | 2.4.66 | 1.0.2zn |
| M6 | 9.45 | E8D009 | 2.4.62 | 1.0.2zj |
| M5 | 9.44 | B7Q004 | 2.4.27 | 1.0.2o |
| M4 | 9.43 | A7F006 | 2.4.27 | 1.0.2o |
| M3 | 9.42 | V75010 | 2.4.27 | 1.0.2o |
| M2 | 9.41 or 9.4_M2 | P90009 | 2.4.27 | 1.0.2o |
| M1 | 9.4M1 | S48012 | 2.4.27 | 1.0.2o |
| M0 | 9.4M0 | S46010 | 2.4.27 | 1.0.2o |
| SAS® 9.4 Maintenance Release | Product Release | Current Hot Fix | Apache Tomcat Version | ActiveMQ Version |
|---|---|---|---|---|
| M9 | 9.53 | P6T004 |
10.1.54 | 6.2.5 |
| M8 | 9.48 | M3P011 |
9.0.117 | 5.19.6 |
| M7 (22w08 and later) | 9.47 | M3B010 |
9.0.117 | 5.15.16 |
| M7 (before 22w08) | 9.46 | I9U003 |
8.5.58 | 5.15.16 |
| M6 | 9.45 | E3V008 | 8.5.58 | 5.15.16 |
| M5 | 9.44 | B7P005 | 8.5.23 | --- |
| M4 | 9.43 | B1C005 | 8.0.47 | --- |
| M3 | 9.42 | W43008 | 7.0.82 | --- |
| M2 | 9.41 | R94007 | 7.0.82 | --- |
| M1 | N/A | N/A | N/A | --- |
| M0 | 9.4 | P38005 | 7.0.82 | --- |
| SAS® 9.4 Maintenance Release | Product Release | Current Hot Fix | Apache Tomcat Version |
| M9 | 2.5M6 | P6R005 | 10.1.47 |
| M8 | 2.5M5 | M2T014 | 9.0.117 |
| M7 | 2.5M4 | J9V020 | 9.0.110 |
| M6 | 2.5M3 | E8M011 | 9.0.22 |
| M5 | 2.5M2 | B7R007 | 8.5.35 |
| M4 | 2.5M1 | A8X009 | 8.5.32 |
| M3 | 2.5M0 | V76019 | 8.5.32 |
| M2 | 2.3M0 | S45014 | 8.5.32 |
| M1 | 2.1M1 | S48012 | 8.5.32 |
| M0 | 2.1M0 | S46010 | 8.5.32 |