Severity: Critical/High/Medium
Description: SAS Web Server 9.47 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.
See KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS® 9.4.
Addressed in hot fix M1V009
Addressed in hot fix M1V008
| CVE-2025-15467 | CVE-2025-55753 | CVE-2025-58098 | CVE-2025-59775 | CVE-2025-65082 |
| CVE-2025-66200 |
Addressed in hot fix M1V007
| CVE-2025-9230 | CVE-2025-9232 |
Addressed in hot fix M1V006
| CVE-2024-9143 | CVE-2024-13176 |
Addressed in hot fix M1V005
| CVE-2024-2511 | CVE-2024-4603 | CVE-2024-4741 | CVE-2024-36387 | CVE-2024-38472 |
| CVE-2024-38473 | CVE-2024-38474 | CVE-2024-38475 | CVE-2024-38476 | CVE-2024-38477 |
| CVE-2024-39573 | CVE-2024-39884 | CVE-2024-40725 | CVE-2024-40898 |
Addressed in hot fix M1V004
| CVE-2023-5678 | CVE-2023-38709 | CVE-2024-0727 | CVE-2024-24795 | CVE-2024-27316 |
Addressed in hot fix M1V003
| CVE-2023-5363 | CVE-2023-31122 | CVE-2023-43622 | CVE-2023-45802 |
Addressed in hot fix M1V002
| CVE-2023-2650 |
Addressed in hot fix M1V001
| CVE-2006-20001 | CVE-2022-36760 | CVE-2022-37436 | CVE-2023-25690 | CVE-2023-27522 |
Potential Impact: See the CVE records for additional information.