Severity: Critical/High/Medium/Low
Description:
SAS® Environment Manager 2.5_M5 and SAS® Environment Manager Agent 2.5_M5 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.
See KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS® 9.4.
Addressed in hot fix M2T015, M2U012
Addressed in hot fix M2T014
| CVE-2026-24733 | CVE-2026-24734 | CVE-2025-66614 |
Addressed in hot fix M2T013
| CVE-2025-48924 |
Addressed in hot fix M2T012
| CVE-2023-1932 | CVE-2025-35036 |
Addressed in hot fix M2T011, M2U009
| CVE-2014-9390 | CVE-2025-46701 | CVE-2025-48976 | CVE-2025-48988 | CVE-2025-48989 |
| CVE-2025-49124 | CVE-2025-49125 | CVE-2025-52434 | CVE-2025-52520 | CVE-2025-53506 |
Addressed in hot fix M2T010, M2U008
| CVE-2024-38829 | CVE-2025-31650 | CVE-2025-46701 | CVE-2025-48734 | CVE-2025-48924 |
| CVE-2025-48976 | CVE-2025-48988 | CVE-2025-48989 | CVE-2025-49124 | CVE-2025-49125 |
| CVE-2025-52434 | CVE-2025-52520 | CVE-2025-53506 | CVE-2025-55668 |
Addressed in hot fix M2T009, M2U007
| CVE-2023-5072 | CVE-2024-25638 | CVE-2024-38819 | CVE-2024-38820 | CVE-2024-38821 |
| CVE-2024-38827 | CVE-2024-47072 | CVE-2025-23184 | CVE-2025-24813 |
Addressed in hot fix M2T008
| CVE-2024-50379 | CVE-2024-52316 |
Addressed in hot fix M2T007
| CVE-2024-28752 | CVE-2024-29736 | CVE-2024-34750 |
Addressed in hot fix M2T005, M2U004
| CVE-2023-34042 | CVE-2023-35116 | CVE-2023-49735 | CVE-2024-1597 | CVE-2024-22243 |
| CVE-2024-22262 | CVE-2024-23672 | CVE-2024-24549 |
Addressed in hot fix M2T004
| CVE-2023-41080 | CVE-2023-42794 | CVE-2023-42795 | CVE-2023-44487 | CVE-2023-45648 |
| CVE-2023-46589 |
Addressed in hot fix M2T003
| CVE-2023-46604 |
Addressed in hot fix M2T002, M2U002
| CVE-2022-41946 | CVE-2023-20860 | CVE-2023-20861 | CVE-2023-20862 |
Addressed in hot fix M2T001, M2U001
| CVE-2007-6758 | CVE-2018-8046 | CVE-2020-36518 | CVE-2022-22970 | CVE-2022-23437 |
| CVE-2022-40151 | CVE-2022-40152 | CVE-2023-24998 |
Potential Impact: See the CVE records for additional information.