SAS® 9.4M8 (TS1M8) contains versions of ActiveMQ and third‑party components with known security vulnerabilities


Severity: High

Description: SAS 9.4M8 includes a version of Apache ActiveMQ that is affected by the following vulnerabilities:

In addition, several third‑party components included with ActiveMQ require updates to address known vulnerabilities and maintain compatibility with the latest security standards. These include the following:

Although the Apache Tomcat version is not being updated as part of Q1 maintenance, the tomcat‑juli update is included in this distribution to address customer concerns.

Potential Impact: See the CVE records for additional information.