SAS® Environment Manager and SAS® Environment Manager Agent 2.5_M6 (SAS® 9.4 TS1M9) hot fixes address security vulnerabilities


Severity: Critical/High/Medium/Low


Description: 

SAS® Environment Manager 2.5_M6 and SAS® Environment Manager Agent 2.5_M6 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.

See KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS® 9.4.

 

Addressed in hot fix P6R006, P6S004

CVE-2025-66614CVE-2026-24733CVE-2026-24734CVE-2026-24880CVE-2026-25854
CVE-2026-29129CVE-2026-29145CVE-2026-29146CVE-2026-32990CVE-2026-34477
CVE-2026-34479CVE-2026-34480CVE-2026-34483CVE-2026-34486CVE-2026-34487
CVE-2026-34500CVE-2026-42198   

 

Addressed in hot fix P6R005, P6S003

CVE-2025-68161CVE-2026-22732

 

Addressed in hot fix P6R003

CVE-2025-48989CVE-2025-55752CVE-2025-55754CVE-2025-61795CVE-2025-7962

 

Addressed in hot fix P6R002, P6S002

CVE-2014-9390CVE-2025-41249

 

Addressed in hot fix P6R001, P6S001

CVE-2025-22233CVE-2025-22234CVE-2025-31651CVE-2025-41234CVE-2025-46701
CVE-2025-48734CVE-2025-48924CVE-2025-48988CVE-2025-49125CVE-2025-52520

 

Potential Impact: See the CVE records for additional information.