Problem Note 70944: SAS® Environment Manager contains Apache CXF, Apache ActiveMQ 5.17.x, and Apache Tomcat 9.0.89, which have security vulnerabilities
Severity: High
Description: SAS Environment Manager contains versions of CXF, ActiveMQ, and Tomcat that are known to be affected by the following vulnerabilities:
CVE-2024-34750
CVE-2024-29736
CVE-2024-28752
Potential Impact: Refer to the CVE records listed above for details.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS Environment Manager | Solaris for x64 | 2.5_M5 | | 9.4 TS1M8 | |
Linux for x64 | 2.5_M5 | | 9.4 TS1M8 | |
64-bit Enabled AIX | 2.5_M5 | | 9.4 TS1M8 | |
64-bit Enabled Solaris | 2.5_M5 | | 9.4 TS1M8 | |
Microsoft® Windows® for x64 | 2.5_M5 | | 9.4 TS1M8 | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
The following vulnerabilities are present:
CVE-2024-34750
CVE-2024-29736
CVE-2024-28752
These issues can be resolved by applying the attached hot fix.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2024-09-03 08:09:06 |
Date Created: | 2024-08-26 14:11:35 |