Severity: Critical/High/Medium/Low
Description: SAS Web Application Server 9.48 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.
See SAS KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS® 9.4.
Addressed in hot fix M3P012
Addressed in hot fix M3P011
| CVE-2025-66614 | CVE-2025-66168 | CVE-2026-24733 | CVE-2026-24734 | CVE-2026-29145 |
| CVE-2026-29146 | CVE-2026-33227 | CVE-2026-34197 | CVE-2026-34487 | CVE-2026-34500 |
| CVE-2026-39304 | CVE-2026-40466 | CVE-2026-41043 | CVE-2026-41044 |
Addressed in hot fix M3P010
| CVE-2020-11971 | CVE-2024-38816 | CVE-2024-38819 | CVE-2024-38820 | CVE-2024-38828 |
| CVE-2025-41242 | CVE-2025-41249 | CVE-2025-55754 | CVE-2025-68161 | CVE-2026-23901 |
| CVE-2026-23903 |
Addressed in hot fix M3P009
| CVE-2025-48989 | CVE-2025-55752 | CVE-2025-55754 | CVE-2025-61795 |
Addressed in hot fix M3P008
| CVE-2025-27533 | CVE-2025-46701 | CVE-2025-48976 | CVE-2025-48988 | CVE-2025-49124 |
| CVE-2025-49125 | CVE-2025-52434 | CVE-2025-52520 | CVE-2025-53506 |
Addressed in hot fix M3P007
| CVE-2020-11971 | CVE-2024-6763 | CVE-2024-8184 | CVE-2024-38808 | CVE-2024-38809 |
| CVE-2024-38816 | CVE-2024-38819 | CVE-2024-38820 | CVE-2024-38828 | CVE-2024-47072 |
| CVE-2025-24813 |
Addressed in hot fix M3P006
| CVE-2024-52316 |
Addressed in hot fix M3P005
| CVE-2020-11971 | CVE-2022-45143 | CVE-2023-35116 | CVE-2023-46589 | CVE-2023-46749 |
| CVE-2023-46750 | CVE-2024-22243 | CVE-2024-22259 | CVE-2024-23672 | CVE-2024-34750 |
Addressed in hot fix M3P004
| CVE-2024-23672 | CVE-2024-24549 |
Addressed in hot fix M3P003
| CVE-2023-41080 | CVE-2023-42794 | CVE-2023-42795 | CVE-2023-44487 | CVE-2023-45648 |
| CVE-2023-46589 |
Addressed in hot fix M3P002
| CVE-2023-46604 |
Addressed in hot fix M3P001
| CVE-2023-24998 |
Potential Impact: See the CVE records for additional information.