<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Update ActiveMQ on SAS 9.4 Server for CVE-2023-46604 in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920706#M28237</link>
    <description>You could restart your host, that should release any open files.</description>
    <pubDate>Mon, 18 Mar 2024 13:01:51 GMT</pubDate>
    <dc:creator>gwootton</dc:creator>
    <dc:date>2024-03-18T13:01:51Z</dc:date>
    <item>
      <title>Update ActiveMQ on SAS 9.4 Server for CVE-2023-46604</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920490#M28229</link>
      <description>&lt;P&gt;A recent vulnerability scan has identified the version of ActiveMQ currently running on our SAS 9.4 server to be vulnerable.&lt;/P&gt;&lt;P&gt;I found a relevant article (&lt;A href="https://communities.sas.com/t5/SAS-Hot-Fix-Announcements/Updates-available-for-SAS-Environment-Manager-2-5-M4-Hot-fix/ba-p/918947" target="_blank" rel="noopener"&gt;Updates available for SAS Environment Manager 2.5_M4 : Hot fix J9V014 - SAS Support Communities&lt;/A&gt;) in the community forum, but my questions are:&lt;/P&gt;&lt;P&gt;Will updating the SAS Environment Manager remediate the ActiveMQ vulnerability?&lt;/P&gt;&lt;P&gt;How do I run/access SAS Environment Manager? I'm not seeing it under SAS in Start menu.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 19:00:02 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920490#M28229</guid>
      <dc:creator>aalborz-ema</dc:creator>
      <dc:date>2024-03-15T19:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Update ActiveMQ on SAS 9.4 Server for CVE-2023-46604</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920503#M28230</link>
      <description>Here's the SAS statement on the vulnerability along with remediation steps: &lt;BR /&gt;&lt;A href="https://support.sas.com/en/security-bulletins/apache-activemq-vulnerability.html" target="_blank"&gt;https://support.sas.com/en/security-bulletins/apache-activemq-vulnerability.html&lt;/A&gt;</description>
      <pubDate>Fri, 15 Mar 2024 19:25:37 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920503#M28230</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2024-03-15T19:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Update ActiveMQ on SAS 9.4 Server for CVE-2023-46604</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920522#M28231</link>
      <description>&lt;P&gt;Thanks Greg! I figured out the SAS Deployment Manager HotFix install for the ActiveMQ client.&lt;/P&gt;&lt;P&gt;However, even after stopping all the SAS services, when I run the hotfix thru via DM, it's complaining about open/in use files, including activemq client. How do I get around that?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 21:40:23 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920522#M28231</guid>
      <dc:creator>aalborz-ema</dc:creator>
      <dc:date>2024-03-15T21:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Update ActiveMQ on SAS 9.4 Server for CVE-2023-46604</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920706#M28237</link>
      <description>You could restart your host, that should release any open files.</description>
      <pubDate>Mon, 18 Mar 2024 13:01:51 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Update-ActiveMQ-on-SAS-9-4-Server-for-CVE-2023-46604/m-p/920706#M28237</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2024-03-18T13:01:51Z</dc:date>
    </item>
  </channel>
</rss>

