SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 70944: SAS® Environment Manager contains Apache CXF, Apache ActiveMQ 5.17.x, and Apache Tomcat 9.0.89, which have security vulnerabilities

DetailsHotfixAboutRate It

Severity: High

Description: SAS Environment Manager contains versions of CXF, ActiveMQ, and Tomcat that are known to be affected by the following vulnerabilities:

CVE-2024-34750

CVE-2024-29736

CVE-2024-28752

Potential Impact: Refer to the CVE records listed above for details. 

Click the Hot Fix tab in this note to access the hot fix for this issue. 



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Environment ManagerSolaris for x642.5_M59.4 TS1M8
Linux for x642.5_M59.4 TS1M8
64-bit Enabled AIX2.5_M59.4 TS1M8
64-bit Enabled Solaris2.5_M59.4 TS1M8
Microsoft® Windows® for x642.5_M59.4 TS1M8
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.