SAS® Environment Manager and SAS® Environment Manager Agent 2.5_M5 (SAS® 9.4 TS1M8) hot fixes address security vulnerabilities


Severity: Critical/High/Medium/Low


Description: 

SAS® Environment Manager 2.5_M5 and SAS® Environment Manager Agent 2.5_M5 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.

See KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS® 9.4.

 

Addressed in hot fix M2T015, M2U012

CVE-2026-33227CVE-2026-34197CVE-2026-34477CVE-2026-34479CVE-2026-34480
CVE-2026-39304CVE-2026-40466CVE-2026-41044CVE-2026-41720CVE-2026-42198
CVE-2026-42588CVE-2026-45505CVE-2026-46605CVE-2026-49270CVE-2026-49844
CVE-2026-54512CVE-2026-54513CVE-2026-54514CVE-2026-54515CVE-2025-68161

 

Addressed in hot fix M2T014

CVE-2026-24733CVE-2026-24734CVE-2025-66614

 

Addressed in hot fix M2T013

CVE-2025-48924

 

Addressed in hot fix M2T012

CVE-2023-1932CVE-2025-35036

 

Addressed in hot fix M2T011, M2U009

CVE-2014-9390CVE-2025-46701CVE-2025-48976CVE-2025-48988CVE-2025-48989
CVE-2025-49124CVE-2025-49125CVE-2025-52434CVE-2025-52520CVE-2025-53506

 

Addressed in hot fix M2T010, M2U008

CVE-2024-38829CVE-2025-31650CVE-2025-46701CVE-2025-48734CVE-2025-48924
CVE-2025-48976CVE-2025-48988CVE-2025-48989CVE-2025-49124CVE-2025-49125
CVE-2025-52434CVE-2025-52520CVE-2025-53506CVE-2025-55668 

 

Addressed in hot fix M2T009, M2U007

 CVE-2023-5072 CVE-2024-25638 CVE-2024-38819CVE-2024-38820CVE-2024-38821
CVE-2024-38827CVE-2024-47072CVE-2025-23184CVE-2025-24813 

 

Addressed in hot fix M2T008

CVE-2024-50379CVE-2024-52316

 

Addressed in hot fix M2T007

CVE-2024-28752CVE-2024-29736CVE-2024-34750

 

Addressed in hot fix M2T005, M2U004

CVE-2023-34042CVE-2023-35116CVE-2023-49735CVE-2024-1597CVE-2024-22243
CVE-2024-22262CVE-2024-23672CVE-2024-24549  

 

Addressed in hot fix M2T004

CVE-2023-41080CVE-2023-42794CVE-2023-42795CVE-2023-44487CVE-2023-45648
CVE-2023-46589    

 

Addressed in hot fix M2T003

CVE-2023-46604

 

Addressed in hot fix M2T002, M2U002

CVE-2022-41946CVE-2023-20860CVE-2023-20861CVE-2023-20862

 

Addressed in hot fix M2T001, M2U001

CVE-2007-6758CVE-2018-8046CVE-2020-36518CVE-2022-22970CVE-2022-23437
CVE-2022-40151CVE-2022-40152CVE-2023-24998  


Potential Impact: See the CVE records for additional information.