Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Manager Server MEDIUM 5.3
CVE-2022-31248

A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to disc…

Fix: 4.1.46-1 / 4.2.37-1+
Fix from $1,600 2022-06-22
Manager Server HIGH 7.5
CVE-2022-21952

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote atta…

Fix: 4.1.46 / 4.2.37+
Fix from $1,950 2022-06-22
Rancher MEDIUM 6.8
CVE-2022-21951

A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network d…

Fix: 2.5.14 / 2.6.5+
Fix from $1,600 2022-05-25
Rancher HIGH 7.2
CVE-2021-36784

A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affec…

Fix: 2.5.13 / 2.6.4+
Fix from $1,950 2022-05-02
Rancher MEDIUM 5.4
CVE-2021-4200

A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. …

Fix: 2.5.13 / 2.6.4+
Fix from $1,600 2022-05-02
Rancher HIGH 7.5
CVE-2021-36778

A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to thei…

Fix: 2.5.12 / 2.6.3+
Fix from $1,950 2022-05-02
Rancher Desktop HIGH 8.8
CVE-2022-21947

A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API…

Fix: 1.2.1+
Fix from $1,950 2022-04-01
Rancher K3s MEDIUM 6.5
CVE-2021-32001

K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the cluster's confidential keyin…

Mitigation only
Fix from $1,600 2021-07-28
Linux Enterprise Server HIGH 7.1
CVE-2021-32000

A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Serve…

Patch available
Fix from $1,950 2021-07-28
Arpwatch HIGH 7.8
CVE-2021-25321

A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenSta…

Fix: 2.1a15+
Fix from $1,950 2021-06-30
Hawk2 HIGH 7.8
CVE-2021-25314

A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterpris…

Fix: 2.6.3+
Fix from $1,950 2021-04-14
Rancher MEDIUM 6.1
CVE-2021-25313

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute Ja…

Fix: 2.5.6+
Fix from $1,600 2021-03-05
Salt Netapi Client CRITICAL 9.3
CVE-2020-8028

A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy …

Fix: 0.16.0-4.14.1 / 0.17.0-3.3.2+
Fix from $2,300 2020-09-17
Linux Enterprise High Performance Computing CRITICAL 9.3
CVE-2020-8025

A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Ser…

No fix yet
Fix from $2,300 2020-08-07
Linux Enterprise Desktop HIGH 7.8
CVE-2020-8018

A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server …

Mitigation only
Fix from $1,950 2020-05-04
Openstack Cloud HIGH 7.8
CVE-2018-17954

An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8…

Mitigation only
Fix from $1,950 2020-04-03
Linux Enterprise Server HIGH 7.8
CVE-2019-18897

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; …

Mitigation only
Fix from $1,950 2020-03-02
Studio Onsite HIGH 8.1
CVE-2017-14807

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite a…

Fix: after 1.3.17-56.6.3
Fix from $1,950 2020-01-27
Studio Onsite MEDIUM 5.9
CVE-2017-14806

A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the reposit…

Fix: after 1.3.17-56.6.3
Fix from $1,600 2020-01-27
Obs Service Tar Scm HIGH 7.5
CVE-2018-12476

Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with contro…

Fix: 0.9.2.1537788075.fefaa74+
Fix from $1,950 2020-01-27
Mailman HIGH 7.8
CVE-2019-3693

A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1…

Fix: 2.1.15-9.6.15.1 / 2.1.17-3.11.1+
Fix from $1,950 2020-01-24
Inn HIGH 7.8
CVE-2019-3692

The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via sym…

Fix: after 2.6.2-2.2
Fix from $1,950 2020-01-24
Trousers HIGH 7.8
CVE-2019-18898

UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local a…

Fix: 0.3.14-6.3.1 / 0.3.14-7.1+
Fix from $1,950 2020-01-23
Openqa MEDIUM 6.1
CVE-2019-3686

openQA before commit c172e8883d8f32fced5e02f9b6faaacc913df27b was vulnerable to XSS in the distri and version parameter. This was reported through th…

Fix: 2019-07-22+
Fix from $1,600 2020-01-17
Openstack Cloud HIGH 8.8
CVE-2019-3683

The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/k…

Fix: 2019-02-18+
Fix from $1,950 2020-01-17
Caas Platform HIGH 7.8
CVE-2019-3682

The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.

Mitigation only
Fix from $1,950 2020-01-17
Suse Linux Enterprise Server HIGH 7.1
CVE-2019-3688

The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterpris…

Mitigation only
Fix from $1,950 2019-10-07
Rancher MEDIUM 6.1
CVE-2019-13209

Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Ranch…

Fix: after 2.2.4
Fix from $1,600 2019-09-04
Rancher CRITICAL 9.8
CVE-2019-11202

An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When…

Fix: after 2.2.1
Fix from $2,300 2019-07-30
Rancher HIGH 8.8
CVE-2019-12274

In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node …

Fix: after 2.2.3
Fix from $1,950 2019-06-06