Severity: Critical/High/Medium/Low
Description:
SAS® Environment Manager 2.5_M6 and SAS® Environment Manager Agent 2.5_M6 hot fixes address the following security vulnerabilities. These hot fixes are cumulative; therefore, only the most recent hot fix is required to address all vulnerabilities listed below.
See KB0046220 for the current supported Apache HTTP Server (httpd), OpenSSL and Apache Tomcat versions in SAS® 9.4.
Addressed in hot fix P6R006, P6S004
Addressed in hot fix P6R005, P6S003
| CVE-2025-68161 | CVE-2026-22732 |
Addressed in hot fix P6R003
| CVE-2025-48989 | CVE-2025-55752 | CVE-2025-55754 | CVE-2025-61795 | CVE-2025-7962 |
Addressed in hot fix P6R002, P6S002
| CVE-2014-9390 | CVE-2025-41249 |
Addressed in hot fix P6R001, P6S001
| CVE-2025-22233 | CVE-2025-22234 | CVE-2025-31651 | CVE-2025-41234 | CVE-2025-46701 |
| CVE-2025-48734 | CVE-2025-48924 | CVE-2025-48988 | CVE-2025-49125 | CVE-2025-52520 |
Potential Impact: See the CVE records for additional information.