Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 4 |
CVE-ID | CVE-2020-26217 CVE-2020-26258 CVE-2020-26259 CVE-2021-3757 CVE-2020-28477 |
CWE-ID | CWE-78 CWE-918 CWE-20 CWE-94 |
Exploitation vector | Network |
Public exploit |
Public exploit code for vulnerability #1 is available. Public exploit code for vulnerability #2 is available. Public exploit code for vulnerability #3 is available. |
Vulnerable software |
SUSE Linux Enterprise Module for SUSE Manager Proxy Operating systems & Components / Operating system SUSE Linux Enterprise Module for SUSE Manager Server Operating systems & Components / Operating system spacewalk-proxy-salt Operating systems & Components / Operating system package or component spacewalk-proxy-redirect Operating systems & Components / Operating system package or component spacewalk-proxy-package-manager Operating systems & Components / Operating system package or component spacewalk-proxy-management Operating systems & Components / Operating system package or component spacewalk-proxy-installer Operating systems & Components / Operating system package or component spacewalk-proxy-common Operating systems & Components / Operating system package or component spacewalk-proxy-broker Operating systems & Components / Operating system package or component spacewalk-client-setup Operating systems & Components / Operating system package or component spacewalk-check Operating systems & Components / Operating system package or component python3-spacewalk-client-setup Operating systems & Components / Operating system package or component python3-spacewalk-check Operating systems & Components / Operating system package or component python3-mgr-osad Operating systems & Components / Operating system package or component mgr-osad Operating systems & Components / Operating system package or component xstream Operating systems & Components / Operating system package or component xpp3-minimal Operating systems & Components / Operating system package or component xpp3 Operating systems & Components / Operating system package or component uyuni-config-modules Operating systems & Components / Operating system package or component susemanager-web-libs Operating systems & Components / Operating system package or component susemanager-sls Operating systems & Components / Operating system package or component susemanager-schema Operating systems & Components / Operating system package or component susemanager-docs_en-pdf Operating systems & Components / Operating system package or component susemanager-docs_en Operating systems & Components / Operating system package or component susemanager-doc-indexes Operating systems & Components / Operating system package or component subscription-matcher Operating systems & Components / Operating system package or component spacewalk-utils-extras Operating systems & Components / Operating system package or component spacewalk-utils Operating systems & Components / Operating system package or component spacewalk-taskomatic Operating systems & Components / Operating system package or component spacewalk-java-postgresql Operating systems & Components / Operating system package or component spacewalk-java-lib Operating systems & Components / Operating system package or component spacewalk-java-config Operating systems & Components / Operating system package or component spacewalk-java Operating systems & Components / Operating system package or component spacewalk-html Operating systems & Components / Operating system package or component spacewalk-config Operating systems & Components / Operating system package or component spacewalk-client-tools Operating systems & Components / Operating system package or component spacewalk-base-minimal-config Operating systems & Components / Operating system package or component spacewalk-base-minimal Operating systems & Components / Operating system package or component spacewalk-base Operating systems & Components / Operating system package or component spacewalk-backend-xmlrpc Operating systems & Components / Operating system package or component spacewalk-backend-xml-export-libs Operating systems & Components / Operating system package or component spacewalk-backend-tools Operating systems & Components / Operating system package or component spacewalk-backend-sql-postgresql Operating systems & Components / Operating system package or component spacewalk-backend-sql Operating systems & Components / Operating system package or component spacewalk-backend-server Operating systems & Components / Operating system package or component spacewalk-backend-package-push-server Operating systems & Components / Operating system package or component spacewalk-backend-iss-export Operating systems & Components / Operating system package or component spacewalk-backend-iss Operating systems & Components / Operating system package or component spacewalk-backend-config-files-tool Operating systems & Components / Operating system package or component spacewalk-backend-config-files-common Operating systems & Components / Operating system package or component spacewalk-backend-config-files Operating systems & Components / Operating system package or component spacewalk-backend-applet Operating systems & Components / Operating system package or component spacewalk-backend-app Operating systems & Components / Operating system package or component spacewalk-backend Operating systems & Components / Operating system package or component python3-spacewalk-client-tools Operating systems & Components / Operating system package or component python3-rhnlib Operating systems & Components / Operating system package or component python3-mgr-osa-dispatcher Operating systems & Components / Operating system package or component python3-mgr-osa-common Operating systems & Components / Operating system package or component py26-compat-salt Operating systems & Components / Operating system package or component prometheus-formula Operating systems & Components / Operating system package or component prometheus-exporters-formula Operating systems & Components / Operating system package or component mgr-osa-dispatcher Operating systems & Components / Operating system package or component mgr-libmod Operating systems & Components / Operating system package or component grafana-formula Operating systems & Components / Operating system package or component cobbler Operating systems & Components / Operating system package or component susemanager-tools Operating systems & Components / Operating system package or component susemanager Operating systems & Components / Operating system package or component smdba Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 4 vulnerabilities.
EUVDB-ID: #VU49039
Risk: Medium
CVSSv4.0: 7.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2020-26217
CWE-ID:
CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Exploit availability: Yes
DescriptionThe vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation, when processing blacklists. A remote user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationUpdate the affected package SUSE Manager Server 4.1 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Module for SUSE Manager Proxy: 4.1
SUSE Linux Enterprise Module for SUSE Manager Server: 4.1
spacewalk-proxy-salt: before 4.1.4-3.9.4
spacewalk-proxy-redirect: before 4.1.4-3.9.4
spacewalk-proxy-package-manager: before 4.1.4-3.9.4
spacewalk-proxy-management: before 4.1.4-3.9.4
spacewalk-proxy-installer: before 4.1.6-3.3.2
spacewalk-proxy-common: before 4.1.4-3.9.4
spacewalk-proxy-broker: before 4.1.4-3.9.4
spacewalk-client-setup: before 4.1.9-4.12.4
spacewalk-check: before 4.1.9-4.12.4
python3-spacewalk-client-setup: before 4.1.9-4.12.4
python3-spacewalk-check: before 4.1.9-4.12.4
python3-mgr-osad: before 4.1.5-2.9.4
mgr-osad: before 4.1.5-2.9.4
xstream: before 1.4.15-3.5.2
xpp3-minimal: before 1.1.4c-11.2.2
xpp3: before 1.1.4c-11.2.2
uyuni-config-modules: before 4.1.21-3.26.2
susemanager-web-libs: before 4.1.23-3.18.6
susemanager-sls: before 4.1.21-3.26.2
susemanager-schema: before 4.1.19-3.24.4
susemanager-docs_en-pdf: before 4.1-11.28.2
susemanager-docs_en: before 4.1-11.28.2
susemanager-doc-indexes: before 4.1-11.28.4
subscription-matcher: before 0.26-3.6.2
spacewalk-utils-extras: before 4.1.14-3.12.2
spacewalk-utils: before 4.1.14-3.12.2
spacewalk-taskomatic: before 4.1.30-3.31.7
spacewalk-java-postgresql: before 4.1.30-3.31.7
spacewalk-java-lib: before 4.1.30-3.31.7
spacewalk-java-config: before 4.1.30-3.31.7
spacewalk-java: before 4.1.30-3.31.7
spacewalk-html: before 4.1.23-3.18.6
spacewalk-config: before 4.1.5-3.3.2
spacewalk-client-tools: before 4.1.9-4.12.4
spacewalk-base-minimal-config: before 4.1.23-3.18.6
spacewalk-base-minimal: before 4.1.23-3.18.6
spacewalk-base: before 4.1.23-3.18.6
spacewalk-backend-xmlrpc: before 4.1.21-4.22.7
spacewalk-backend-xml-export-libs: before 4.1.21-4.22.7
spacewalk-backend-tools: before 4.1.21-4.22.7
spacewalk-backend-sql-postgresql: before 4.1.21-4.22.7
spacewalk-backend-sql: before 4.1.21-4.22.7
spacewalk-backend-server: before 4.1.21-4.22.7
spacewalk-backend-package-push-server: before 4.1.21-4.22.7
spacewalk-backend-iss-export: before 4.1.21-4.22.7
spacewalk-backend-iss: before 4.1.21-4.22.7
spacewalk-backend-config-files-tool: before 4.1.21-4.22.7
spacewalk-backend-config-files-common: before 4.1.21-4.22.7
spacewalk-backend-config-files: before 4.1.21-4.22.7
spacewalk-backend-applet: before 4.1.21-4.22.7
spacewalk-backend-app: before 4.1.21-4.22.7
spacewalk-backend: before 4.1.21-4.22.7
python3-spacewalk-client-tools: before 4.1.9-4.12.4
python3-rhnlib: before 4.1.3-4.3.2
python3-mgr-osa-dispatcher: before 4.1.5-2.9.4
python3-mgr-osa-common: before 4.1.5-2.9.4
py26-compat-salt: before 2016.11.10-6.11.2
prometheus-formula: before 0.3.1-3.6.2
prometheus-exporters-formula: before 0.9.0-3.19.2
mgr-osa-dispatcher: before 4.1.5-2.9.4
mgr-libmod: before 4.1.7-3.16.2
grafana-formula: before 0.4.0-3.6.2
cobbler: before 3.0.0+git20190806.32c4bae0-5.6.4
susemanager-tools: before 4.1.24-3.20.2
susemanager: before 4.1.24-3.20.2
smdba: before 1.7.8-0.3.6.2
CPE2.3https://www.suse.com/support/update/announcement/2021/suse-su-20210906-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU49041
Risk: Medium
CVSSv4.0: 5.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2020-26258
CWE-ID:
CWE-918 - Server-Side Request Forgery (SSRF)
Exploit availability: Yes
DescriptionThe disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
MitigationUpdate the affected package SUSE Manager Server 4.1 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Module for SUSE Manager Proxy: 4.1
SUSE Linux Enterprise Module for SUSE Manager Server: 4.1
spacewalk-proxy-salt: before 4.1.4-3.9.4
spacewalk-proxy-redirect: before 4.1.4-3.9.4
spacewalk-proxy-package-manager: before 4.1.4-3.9.4
spacewalk-proxy-management: before 4.1.4-3.9.4
spacewalk-proxy-installer: before 4.1.6-3.3.2
spacewalk-proxy-common: before 4.1.4-3.9.4
spacewalk-proxy-broker: before 4.1.4-3.9.4
spacewalk-client-setup: before 4.1.9-4.12.4
spacewalk-check: before 4.1.9-4.12.4
python3-spacewalk-client-setup: before 4.1.9-4.12.4
python3-spacewalk-check: before 4.1.9-4.12.4
python3-mgr-osad: before 4.1.5-2.9.4
mgr-osad: before 4.1.5-2.9.4
xstream: before 1.4.15-3.5.2
xpp3-minimal: before 1.1.4c-11.2.2
xpp3: before 1.1.4c-11.2.2
uyuni-config-modules: before 4.1.21-3.26.2
susemanager-web-libs: before 4.1.23-3.18.6
susemanager-sls: before 4.1.21-3.26.2
susemanager-schema: before 4.1.19-3.24.4
susemanager-docs_en-pdf: before 4.1-11.28.2
susemanager-docs_en: before 4.1-11.28.2
susemanager-doc-indexes: before 4.1-11.28.4
subscription-matcher: before 0.26-3.6.2
spacewalk-utils-extras: before 4.1.14-3.12.2
spacewalk-utils: before 4.1.14-3.12.2
spacewalk-taskomatic: before 4.1.30-3.31.7
spacewalk-java-postgresql: before 4.1.30-3.31.7
spacewalk-java-lib: before 4.1.30-3.31.7
spacewalk-java-config: before 4.1.30-3.31.7
spacewalk-java: before 4.1.30-3.31.7
spacewalk-html: before 4.1.23-3.18.6
spacewalk-config: before 4.1.5-3.3.2
spacewalk-client-tools: before 4.1.9-4.12.4
spacewalk-base-minimal-config: before 4.1.23-3.18.6
spacewalk-base-minimal: before 4.1.23-3.18.6
spacewalk-base: before 4.1.23-3.18.6
spacewalk-backend-xmlrpc: before 4.1.21-4.22.7
spacewalk-backend-xml-export-libs: before 4.1.21-4.22.7
spacewalk-backend-tools: before 4.1.21-4.22.7
spacewalk-backend-sql-postgresql: before 4.1.21-4.22.7
spacewalk-backend-sql: before 4.1.21-4.22.7
spacewalk-backend-server: before 4.1.21-4.22.7
spacewalk-backend-package-push-server: before 4.1.21-4.22.7
spacewalk-backend-iss-export: before 4.1.21-4.22.7
spacewalk-backend-iss: before 4.1.21-4.22.7
spacewalk-backend-config-files-tool: before 4.1.21-4.22.7
spacewalk-backend-config-files-common: before 4.1.21-4.22.7
spacewalk-backend-config-files: before 4.1.21-4.22.7
spacewalk-backend-applet: before 4.1.21-4.22.7
spacewalk-backend-app: before 4.1.21-4.22.7
spacewalk-backend: before 4.1.21-4.22.7
python3-spacewalk-client-tools: before 4.1.9-4.12.4
python3-rhnlib: before 4.1.3-4.3.2
python3-mgr-osa-dispatcher: before 4.1.5-2.9.4
python3-mgr-osa-common: before 4.1.5-2.9.4
py26-compat-salt: before 2016.11.10-6.11.2
prometheus-formula: before 0.3.1-3.6.2
prometheus-exporters-formula: before 0.9.0-3.19.2
mgr-osa-dispatcher: before 4.1.5-2.9.4
mgr-libmod: before 4.1.7-3.16.2
grafana-formula: before 0.4.0-3.6.2
cobbler: before 3.0.0+git20190806.32c4bae0-5.6.4
susemanager-tools: before 4.1.24-3.20.2
susemanager: before 4.1.24-3.20.2
smdba: before 1.7.8-0.3.6.2
CPE2.3https://www.suse.com/support/update/announcement/2021/suse-su-20210906-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU49040
Risk: Medium
CVSSv4.0: 7.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2020-26259
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: Yes
DescriptionThe vulnerability allows a remote attacker to delete arbitrary files on the system.
The vulnerability exists due to insufficient validation of user-supplied input within the blacklisting feature. A remote attacker can pass specially crafted input to the application and delete arbitrary files on the system.
Update the affected package SUSE Manager Server 4.1 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Module for SUSE Manager Proxy: 4.1
SUSE Linux Enterprise Module for SUSE Manager Server: 4.1
spacewalk-proxy-salt: before 4.1.4-3.9.4
spacewalk-proxy-redirect: before 4.1.4-3.9.4
spacewalk-proxy-package-manager: before 4.1.4-3.9.4
spacewalk-proxy-management: before 4.1.4-3.9.4
spacewalk-proxy-installer: before 4.1.6-3.3.2
spacewalk-proxy-common: before 4.1.4-3.9.4
spacewalk-proxy-broker: before 4.1.4-3.9.4
spacewalk-client-setup: before 4.1.9-4.12.4
spacewalk-check: before 4.1.9-4.12.4
python3-spacewalk-client-setup: before 4.1.9-4.12.4
python3-spacewalk-check: before 4.1.9-4.12.4
python3-mgr-osad: before 4.1.5-2.9.4
mgr-osad: before 4.1.5-2.9.4
xstream: before 1.4.15-3.5.2
xpp3-minimal: before 1.1.4c-11.2.2
xpp3: before 1.1.4c-11.2.2
uyuni-config-modules: before 4.1.21-3.26.2
susemanager-web-libs: before 4.1.23-3.18.6
susemanager-sls: before 4.1.21-3.26.2
susemanager-schema: before 4.1.19-3.24.4
susemanager-docs_en-pdf: before 4.1-11.28.2
susemanager-docs_en: before 4.1-11.28.2
susemanager-doc-indexes: before 4.1-11.28.4
subscription-matcher: before 0.26-3.6.2
spacewalk-utils-extras: before 4.1.14-3.12.2
spacewalk-utils: before 4.1.14-3.12.2
spacewalk-taskomatic: before 4.1.30-3.31.7
spacewalk-java-postgresql: before 4.1.30-3.31.7
spacewalk-java-lib: before 4.1.30-3.31.7
spacewalk-java-config: before 4.1.30-3.31.7
spacewalk-java: before 4.1.30-3.31.7
spacewalk-html: before 4.1.23-3.18.6
spacewalk-config: before 4.1.5-3.3.2
spacewalk-client-tools: before 4.1.9-4.12.4
spacewalk-base-minimal-config: before 4.1.23-3.18.6
spacewalk-base-minimal: before 4.1.23-3.18.6
spacewalk-base: before 4.1.23-3.18.6
spacewalk-backend-xmlrpc: before 4.1.21-4.22.7
spacewalk-backend-xml-export-libs: before 4.1.21-4.22.7
spacewalk-backend-tools: before 4.1.21-4.22.7
spacewalk-backend-sql-postgresql: before 4.1.21-4.22.7
spacewalk-backend-sql: before 4.1.21-4.22.7
spacewalk-backend-server: before 4.1.21-4.22.7
spacewalk-backend-package-push-server: before 4.1.21-4.22.7
spacewalk-backend-iss-export: before 4.1.21-4.22.7
spacewalk-backend-iss: before 4.1.21-4.22.7
spacewalk-backend-config-files-tool: before 4.1.21-4.22.7
spacewalk-backend-config-files-common: before 4.1.21-4.22.7
spacewalk-backend-config-files: before 4.1.21-4.22.7
spacewalk-backend-applet: before 4.1.21-4.22.7
spacewalk-backend-app: before 4.1.21-4.22.7
spacewalk-backend: before 4.1.21-4.22.7
python3-spacewalk-client-tools: before 4.1.9-4.12.4
python3-rhnlib: before 4.1.3-4.3.2
python3-mgr-osa-dispatcher: before 4.1.5-2.9.4
python3-mgr-osa-common: before 4.1.5-2.9.4
py26-compat-salt: before 2016.11.10-6.11.2
prometheus-formula: before 0.3.1-3.6.2
prometheus-exporters-formula: before 0.9.0-3.19.2
mgr-osa-dispatcher: before 4.1.5-2.9.4
mgr-libmod: before 4.1.7-3.16.2
grafana-formula: before 0.4.0-3.6.2
cobbler: before 3.0.0+git20190806.32c4bae0-5.6.4
susemanager-tools: before 4.1.24-3.20.2
susemanager: before 4.1.24-3.20.2
smdba: before 1.7.8-0.3.6.2
CPE2.3https://www.suse.com/support/update/announcement/2021/suse-su-20210906-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU57215
Risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-3757,CVE-2020-28477
CWE-ID:
CWE-94 - Improper Control of Generation of Code ('Code Injection')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request to the application and perform prototype pollution.
Update the affected package SUSE Manager Server 4.1 to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Module for SUSE Manager Proxy: 4.1
SUSE Linux Enterprise Module for SUSE Manager Server: 4.1
spacewalk-proxy-salt: before 4.1.4-3.9.4
spacewalk-proxy-redirect: before 4.1.4-3.9.4
spacewalk-proxy-package-manager: before 4.1.4-3.9.4
spacewalk-proxy-management: before 4.1.4-3.9.4
spacewalk-proxy-installer: before 4.1.6-3.3.2
spacewalk-proxy-common: before 4.1.4-3.9.4
spacewalk-proxy-broker: before 4.1.4-3.9.4
spacewalk-client-setup: before 4.1.9-4.12.4
spacewalk-check: before 4.1.9-4.12.4
python3-spacewalk-client-setup: before 4.1.9-4.12.4
python3-spacewalk-check: before 4.1.9-4.12.4
python3-mgr-osad: before 4.1.5-2.9.4
mgr-osad: before 4.1.5-2.9.4
xstream: before 1.4.15-3.5.2
xpp3-minimal: before 1.1.4c-11.2.2
xpp3: before 1.1.4c-11.2.2
uyuni-config-modules: before 4.1.21-3.26.2
susemanager-web-libs: before 4.1.23-3.18.6
susemanager-sls: before 4.1.21-3.26.2
susemanager-schema: before 4.1.19-3.24.4
susemanager-docs_en-pdf: before 4.1-11.28.2
susemanager-docs_en: before 4.1-11.28.2
susemanager-doc-indexes: before 4.1-11.28.4
subscription-matcher: before 0.26-3.6.2
spacewalk-utils-extras: before 4.1.14-3.12.2
spacewalk-utils: before 4.1.14-3.12.2
spacewalk-taskomatic: before 4.1.30-3.31.7
spacewalk-java-postgresql: before 4.1.30-3.31.7
spacewalk-java-lib: before 4.1.30-3.31.7
spacewalk-java-config: before 4.1.30-3.31.7
spacewalk-java: before 4.1.30-3.31.7
spacewalk-html: before 4.1.23-3.18.6
spacewalk-config: before 4.1.5-3.3.2
spacewalk-client-tools: before 4.1.9-4.12.4
spacewalk-base-minimal-config: before 4.1.23-3.18.6
spacewalk-base-minimal: before 4.1.23-3.18.6
spacewalk-base: before 4.1.23-3.18.6
spacewalk-backend-xmlrpc: before 4.1.21-4.22.7
spacewalk-backend-xml-export-libs: before 4.1.21-4.22.7
spacewalk-backend-tools: before 4.1.21-4.22.7
spacewalk-backend-sql-postgresql: before 4.1.21-4.22.7
spacewalk-backend-sql: before 4.1.21-4.22.7
spacewalk-backend-server: before 4.1.21-4.22.7
spacewalk-backend-package-push-server: before 4.1.21-4.22.7
spacewalk-backend-iss-export: before 4.1.21-4.22.7
spacewalk-backend-iss: before 4.1.21-4.22.7
spacewalk-backend-config-files-tool: before 4.1.21-4.22.7
spacewalk-backend-config-files-common: before 4.1.21-4.22.7
spacewalk-backend-config-files: before 4.1.21-4.22.7
spacewalk-backend-applet: before 4.1.21-4.22.7
spacewalk-backend-app: before 4.1.21-4.22.7
spacewalk-backend: before 4.1.21-4.22.7
python3-spacewalk-client-tools: before 4.1.9-4.12.4
python3-rhnlib: before 4.1.3-4.3.2
python3-mgr-osa-dispatcher: before 4.1.5-2.9.4
python3-mgr-osa-common: before 4.1.5-2.9.4
py26-compat-salt: before 2016.11.10-6.11.2
prometheus-formula: before 0.3.1-3.6.2
prometheus-exporters-formula: before 0.9.0-3.19.2
mgr-osa-dispatcher: before 4.1.5-2.9.4
mgr-libmod: before 4.1.7-3.16.2
grafana-formula: before 0.4.0-3.6.2
cobbler: before 3.0.0+git20190806.32c4bae0-5.6.4
susemanager-tools: before 4.1.24-3.20.2
susemanager: before 4.1.24-3.20.2
smdba: before 1.7.8-0.3.6.2
CPE2.3https://www.suse.com/support/update/announcement/2021/suse-su-20210906-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.