<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log4j Vulnerability - Remediation required for SAS client tools? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787083#M23574</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advice if&amp;nbsp;Log4j Vulnerability Remediation is to be performed for SAS client tools (like SAS Enterprise Guide) and if so what are the steps. In such case we would need to have it fixed for all users who would have installed SAS EG. Please advice.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 11:43:35 GMT</pubDate>
    <dc:creator>judie_c1</dc:creator>
    <dc:date>2021-12-22T11:43:35Z</dc:date>
    <item>
      <title>Log4j Vulnerability - Remediation required for SAS client tools?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787083#M23574</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advice if&amp;nbsp;Log4j Vulnerability Remediation is to be performed for SAS client tools (like SAS Enterprise Guide) and if so what are the steps. In such case we would need to have it fixed for all users who would have installed SAS EG. Please advice.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 11:43:35 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787083#M23574</guid>
      <dc:creator>judie_c1</dc:creator>
      <dc:date>2021-12-22T11:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j Vulnerability - Remediation required for SAS client tools?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787091#M23576</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/366172"&gt;@judie_c1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Here are the links to SAS resources regarding log4j:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.sas.com/content/support/en/security-bulletins/remote-code-execution-vulnerability-cve-2021-44228.html" target="_self"&gt;SAS Statement Regarding Remote Code Execution Vulnerability&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;SAS Blog post&amp;nbsp;&lt;A href="https://blogs.sas.com/content/sgf/2021/12/13/cve-2021-44228-log4j/" target="_self"&gt;Updates on the Apache Log4j CVE-2021-44228 vulnerability&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://communities.sas.com/t5/Administration-and-Deployment/SAS-response-recommendations-for-zero-day-log4j2-CVE-2021-44228/m-p/785489#M23520" target="_self"&gt;Lengthy Community thread with many questions / responses&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps,&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 13:08:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787091#M23576</guid>
      <dc:creator>joeFurbee</dc:creator>
      <dc:date>2021-12-22T13:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j Vulnerability - Remediation required for SAS client tools?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787175#M23579</link>
      <description>&lt;P&gt;A lot will depend on how EG was installed. If it was installed via an EG standalone installer then it is unlikely log4j software is included. I did a quick check on my laptop and can't find it in any EG install directories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the other hand if an installation was done from a full SAS Software Depot and that depot was copied to a client PC hard drive then the depot may contain log4j software. Also if SAS client tools other than EG were installed then it is possible log4j software will be included.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bottom line is you really need to search any local hard drives to be sure. In Windows Explorer search for this - &lt;CODE class="xisDoc-directedUserInput"&gt;log4j-core-2.*.jar&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 22:06:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787175#M23579</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2021-12-22T22:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j Vulnerability - Remediation required for SAS client tools?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787250#M23582</link>
      <description>&lt;P&gt;SAS Enterprise Guide is a Microsoft .Net application.No Log4j patching.&lt;BR /&gt;However for client tools from server (SAS Studio etc) should be covered by patching in the server.&lt;BR /&gt;In case of a doubt SAS Tech Support should be of great help.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 16:14:39 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787250#M23582</guid>
      <dc:creator>Sajid01</dc:creator>
      <dc:date>2021-12-23T16:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j Vulnerability - Remediation required for SAS client tools?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787262#M23583</link>
      <description>&lt;P&gt;EG is, as mentioned, based on .NET, so it will have other vulnerabilities (after all, .NET is from Microsoft &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you have other clients installed locally (Management Console, Information Map Studio, OLAP Cube Studio), these are based on Java and might carry vulnerabilities, although the danger is not as big as on servers (you would have to somehow create a loggable event in those apps - on your own! - that carries a malicious string)&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 16:59:26 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/787262#M23583</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2021-12-23T16:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j Vulnerability - Remediation required for SAS client tools?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/796015#M23792</link>
      <description>&lt;P&gt;is there any order we need to do the log4j remediation? like start with meta, compute and then mid-tier ?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 09:04:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Log4j-Vulnerability-Remediation-required-for-SAS-client-tools/m-p/796015#M23792</guid>
      <dc:creator>muduki</dc:creator>
      <dc:date>2022-02-14T09:04:00Z</dc:date>
    </item>
  </channel>
</rss>

