SAS® Web Server 9.47 (SAS® 9.4 TS1M8) hot fixes address security vulnerabilities


Severity: Critical/High/Medium

Description: SAS Web Server 9.47 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.

See KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS® 9.4.

 

Addressed in hot fix M1V009

CVE-2026-23918CVE-2026-24072CVE-2026-28780CVE-2026-29167CVE-2026-29168
CVE-2026-29169CVE-2026-29170CVE-2026-33006CVE-2026-33007CVE-2026-33523
CVE-2026-33857CVE-2026-34032CVE-2026-34059CVE-2026-34355CVE-2026-34356
CVE-2026-42535CVE-2026-42536CVE-2026-43951CVE-2026-44119CVE-2026-44185
CVE-2026-44186CVE-2026-44631CVE-2026-48913CVE-2026-49975 

 

Addressed in hot fix M1V008

CVE-2025-15467CVE-2025-55753CVE-2025-58098CVE-2025-59775CVE-2025-65082
CVE-2025-66200    

 

Addressed in hot fix M1V007

CVE-2025-9230CVE-2025-9232

 

Addressed in hot fix M1V006

CVE-2024-9143CVE-2024-13176

 

Addressed in hot fix M1V005

CVE-2024-2511CVE-2024-4603CVE-2024-4741CVE-2024-36387CVE-2024-38472
CVE-2024-38473CVE-2024-38474CVE-2024-38475CVE-2024-38476CVE-2024-38477
CVE-2024-39573CVE-2024-39884CVE-2024-40725CVE-2024-40898 

 

Addressed in hot fix M1V004

CVE-2023-5678CVE-2023-38709CVE-2024-0727CVE-2024-24795CVE-2024-27316

 

Addressed in hot fix M1V003

CVE-2023-5363CVE-2023-31122CVE-2023-43622CVE-2023-45802

 

Addressed in hot fix M1V002

CVE-2023-2650

 

Addressed in hot fix M1V001

CVE-2006-20001CVE-2022-36760CVE-2022-37436CVE-2023-25690CVE-2023-27522

 

Potential Impact: See the CVE records for additional information.