Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2022-31255 CVE-2022-43753 CVE-2022-43754 |
CWE-ID | CWE-22 CWE-79 |
Exploitation vector | Network |
Public exploit |
Public exploit code for vulnerability #1 is available. Public exploit code for vulnerability #2 is available. |
Vulnerable software |
SUSE Manager Retail Branch Server Operating systems & Components / Operating system SUSE Manager Server Operating systems & Components / Operating system SUSE Manager Proxy Operating systems & Components / Operating system release-notes-susemanager-proxy Operating systems & Components / Operating system package or component release-notes-susemanager Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU69062
Risk: Medium
CVSSv4.0: 5.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2022-31255
CWE-ID:
CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Exploit availability: Yes
DescriptionThe vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
MitigationUpdate the affected package release-notes-susemanager, release-notes-susemanager-proxy to the latest version.
Vulnerable software versionsSUSE Manager Retail Branch Server: 4.2
SUSE Manager Server: 4.2
SUSE Manager Proxy: 4.2
release-notes-susemanager-proxy: before 4.2.10-150300.3.46.1
release-notes-susemanager: before 4.2.10-150300.3.57.1
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20223879-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU69063
Risk: Medium
CVSSv4.0: 5.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2022-43753
CWE-ID:
CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Exploit availability: Yes
DescriptionThe vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.
MitigationUpdate the affected package release-notes-susemanager, release-notes-susemanager-proxy to the latest version.
Vulnerable software versionsSUSE Manager Retail Branch Server: 4.2
SUSE Manager Server: 4.2
SUSE Manager Proxy: 4.2
release-notes-susemanager-proxy: before 4.2.10-150300.3.46.1
release-notes-susemanager: before 4.2.10-150300.3.57.1
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20223879-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU69064
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-43754
CWE-ID:
CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Exploit availability: No
DescriptionThe disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
MitigationUpdate the affected package release-notes-susemanager, release-notes-susemanager-proxy to the latest version.
Vulnerable software versionsSUSE Manager Retail Branch Server: 4.2
SUSE Manager Server: 4.2
SUSE Manager Proxy: 4.2
release-notes-susemanager-proxy: before 4.2.10-150300.3.46.1
release-notes-susemanager: before 4.2.10-150300.3.57.1
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20223879-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.