Problem Note 71115: SAS® Environment Manager Server contains a version of Freemarker with a known vulnerability
Severity: High
Description: SAS Environment Manager contains a version of Freemarker reported by Snyk to be affected by Server Side Template Injection. No CVE has been recorded for this issue.
Potential Impact: Refer to the previous link for details from Snyk.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS Environment Manager | Microsoft® Windows® for x64 | 2.5_M4 | | 9.4 TS1M7 | |
64-bit Enabled AIX | 2.5_M4 | | 9.4 TS1M7 | |
64-bit Enabled Solaris | 2.5_M4 | | 9.4 TS1M7 | |
HP-UX IPF | 2.5_M4 | | 9.4 TS1M7 | |
Linux for x64 | 2.5_M4 | | 9.4 TS1M7 | |
Solaris for x64 | 2.5_M4 | | 9.4 TS1M7 | |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2025-02-13 08:36:57 |
Date Created: | 2025-01-30 08:19:42 |