<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – SUSE Linux Enterprise Server</title>
  <link>https://cvedaily.com/pages/tags/sles.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sles.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – SUSE Linux Enterprise Server</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:59 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-25702 – A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterpr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25702</guid>
    <pubDate>Thu, 05 Mar 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25702</strong></p>
  <p>A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 before 9c294edb7085fb91650bc12233495a8974c5ff2d.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52869 – Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52869</guid>
    <pubDate>Wed, 08 Jan 2025 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52869</strong></p>
  <p>Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts, and possibly systems administrator created user accounts, are incorrectly assig…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-45154 – A Cleartext Storage of Sensitive Information vulnerability in suppportutils of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45154</guid>
    <pubDate>Wed, 15 Feb 2023 10:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45154</strong></p>
  <p>A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise Server 12 supportutils version 3.0.10-95.51.1CWE-312: Cleartext Storage of Sens…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45153 – An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45153</guid>
    <pubDate>Wed, 15 Feb 2023 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45153</strong></p>
  <p>An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formul…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22643 – An Improper Neutralization of Special Elements used in an OS Command ('OS Comman...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22643</guid>
    <pubDate>Tue, 07 Feb 2023 10:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22643</strong></p>
  <p>An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux Enterprise Server for SAP 15-SP3; openSUSE Leap 15.4 allows attackers that can trick users to use specially crafted REPO_ALIAS, REPO_TYPE or REPO_METADATA_PATH settings to execute code as root. This issue affects: SUSE Linux Enterprise Server for SAP…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31254 – A Incorrect Default Permissions vulnerability in rmt-server-regsharing service o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31254</guid>
    <pubDate>Tue, 07 Feb 2023 10:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31254</strong></p>
  <p>A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31252 – A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31252</guid>
    <pubDate>Thu, 06 Oct 2022 18:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31252</strong></p>
  <p>A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged binary to influence path resolution. This issue affects: SUSE Linux Enterprise Se…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46705 – A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46705</guid>
    <pubDate>Wed, 16 Mar 2022 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46705</strong></p>
  <p>A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to 2.06-18.1.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-32000 – A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32000</guid>
    <pubDate>Wed, 28 Jul 2021 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-32000</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3 clone-master-clean-up version 1.6-4.6.1 and prior versions. SUSE Linux Enterpris…</p>
  <p><strong>CVSS:</strong> 3.2 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25321 – A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25321</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25321</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS arpwatch ve…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18906 – A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18906</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18906</strong></p>
  <p>A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-31998 – A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31998</guid>
    <pubDate>Thu, 10 Jun 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-31998</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior t…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-25317 – A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25317</guid>
    <pubDate>Wed, 05 May 2021 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-25317</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-25316 – A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25316</guid>
    <pubDate>Wed, 14 Apr 2021 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-25316</strong></p>
  <p>A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-SP2 allows local attackers to prevent VM live migrations This issue affects: SUSE Linux Enterprise Server 12-SP5 s390-tools versions prior to 2.1.0-18.29.1. SUSE Linux Enterprise Server 15-SP2 s390-tools versions prior to 2.11.0-9.20.1.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25315 – CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25315</guid>
    <pubDate>Wed, 03 Mar 2021 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25315</strong></p>
  <p>CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE Linux Enterprise Server 15 SP 3 salt versions prior to 3002.2-3. openSUSE Tumbleweed salt version 3002.2-2.1 and prior versions. This issue affects: SUSE L…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8027 – A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8027</guid>
    <pubDate>Thu, 11 Feb 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8027</strong></p>
  <p>A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to overwrite arbitrary files and gain access to the openldap2 configuration This issue affects: SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.37.1. SUSE Linux Enterprise Serv…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8023 – A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8023</guid>
    <pubDate>Tue, 01 Sep 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8023</strong></p>
  <p>A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-349</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8025 – A Incorrect Execution-Assigned Permissions vulnerability in the permissions pack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8025</guid>
    <pubDate>Fri, 07 Aug 2020 10:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8025</strong></p>
  <p>A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissi…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-279</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8019 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8019</guid>
    <pubDate>Mon, 29 Jun 2020 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8019</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server for SAP 12-SP1; openSUSE Backports SLE-15-SP1, openSUSE Leap 15…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8022 – A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8022</guid>
    <pubDate>Mon, 29 Jun 2020 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8022</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterpr…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-8018 – A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8018</guid>
    <pubDate>Mon, 04 May 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-8018</strong></p>
  <p>A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to escalate to root due to a /etc directory owned by the user This issue affects: SUSE Linux Enterprise Server 15 SP1 SLES15-SP1-CAP-Deployment-BYOS version 1.0.1 and prior versions; SLES15-SP1-CHOST-BY…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18905 – A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18905</guid>
    <pubDate>Fri, 03 Apr 2020 11:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18905</strong></p>
  <p>A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue affects: SUSE Linux Enterprise Server 12 autoyast2 version 4.1.9-3.9.1 and prior versions. SUSE Linux Enterprise Server 1…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18904 – A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterpris...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18904</guid>
    <pubDate>Fri, 03 Apr 2020 07:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18904</strong></p>
  <p>A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux E…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3696 – A Improper Limitation of a Pathname to a Restricted Directory vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3696</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3696</strong></p>
  <p>A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development To…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3695 – A Improper Control of Generation of Code vulnerability in the packaging of pcp o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3695</guid>
    <pubDate>Tue, 03 Mar 2020 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3695</strong></p>
  <p>A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux En…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-8013 – A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8013</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-8013</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. This issue affects: SUSE Linu…</p>
  <p><strong>CVSS:</strong> 2.2 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18903 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18903</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18903</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18902 – A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18902</guid>
    <pubDate>Mon, 02 Mar 2020 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18902</strong></p>
  <p>A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked vers…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18901 – A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-help...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18901</guid>
    <pubDate>Mon, 02 Mar 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18901</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE Linux Enterprise Server 12 mariadb versions prior to 10.2.31-3.25.1. SUSE Linux Enterprise Server 15 mariadb versions pri…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18897 – A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18897</guid>
    <pubDate>Mon, 02 Mar 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18897</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 20…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-3698 – UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3698</guid>
    <pubDate>Fri, 28 Feb 2020 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-3698</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This issue affects: SUSE Linux Enterprise Server 12 nagios version 3.5.1-5.27 and prior versions. SUSE Linux Enterprise Server 11…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-20105 – A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20105</guid>
    <pubDate>Mon, 27 Jan 2020 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-20105</strong></p>
  <p>A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-12476 – Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12476</guid>
    <pubDate>Mon, 27 Jan 2020 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-12476</strong></p>
  <p>Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects: SUSE Linux Enterprise Server 15 obs-service-tar_scm versions prior to 0.9.2.1537788075.fefaa74:. openSUSE Factory obs-serv…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18900 – : Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18900</guid>
    <pubDate>Fri, 24 Jan 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18900</strong></p>
  <p>: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1.…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3693 – A symlink following vulnerability in the packaging of mailman in SUSE Linux Ente...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3693</guid>
    <pubDate>Fri, 24 Jan 2020 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3693</strong></p>
  <p>A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12; openSUSE Leap 15.1 allowed local attackers to escalate their privileges from user wwwrun to root. Additionally arbitrary files could be changed to group mailman. This issue affects: SUSE Linux Enterprise Server 11 mailman versions prior to 2.1.15-9.6.15.1. SUSE Linux…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3692 – The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3692</guid>
    <pubDate>Fri, 24 Jan 2020 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3692</strong></p>
  <p>The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.2.47 and prior versions.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-3687 – The permission package in SUSE Linux Enterprise Server allowed all local users t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3687</guid>
    <pubDate>Fri, 24 Jan 2020 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-3687</strong></p>
  <p>The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3691 – A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3691</guid>
    <pubDate>Thu, 23 Jan 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3691</strong></p>
  <p>A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to 0.5.13-4.3.1. openSUSE Factory munge versions prior to 0.5.13-6.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18898 – UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18898</guid>
    <pubDate>Thu, 23 Jan 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18898</strong></p>
  <p>UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14-6.3.1. openSUSE Factory trousers versions prior to 0.3.14-7.1.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-3688 – The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3688</guid>
    <pubDate>Mon, 07 Oct 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-3688</strong></p>
  <p>The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-3689 – The nfs-utils package in SUSE Linux Enterprise Server 12 before and including ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3689</guid>
    <pubDate>Thu, 19 Sep 2019 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-3689</strong></p>
  <p>The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwr…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1602 – A code injection in the supportconfig data collection tool in supportutils in SU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1602</guid>
    <pubDate>Thu, 23 Mar 2017 06:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1602</strong></p>
  <p>A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-4036 – The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4036</guid>
    <pubDate>Mon, 18 Apr 2016 14:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-4036</strong></p>
  <p>The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows local users to obtain sensitive information by reading files in the directory.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2011-3171 – Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3171</guid>
    <pubDate>Fri, 04 Nov 2011 21:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2011-3171</strong></p>
  <p>Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwrite arbitrary files via unknown vectors.</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0988 – pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0988</guid>
    <pubDate>Mon, 18 Apr 2011 17:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0988</strong></p>
  <p>pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-1648 – The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1648</guid>
    <pubDate>Sun, 05 Jul 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-1648</strong></p>
  <p>The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0115 – The Device Mapper multipathing driver (aka multipath-tools or device-mapper-mult...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0115</guid>
    <pubDate>Mon, 30 Mar 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0115</strong></p>
  <p>The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5471 – libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5471</guid>
    <pubDate>Tue, 16 Oct 2007 00:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5471</strong></p>
  <p>libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request.  NOTE: this issue probably affects other daemons that attempt to initialize this library within a chroot configuration or other invalid configuration.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-2752 – The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux Desktop 9 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2752</guid>
    <pubDate>Thu, 01 Jun 2006 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-2752</strong></p>
  <p>The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux Desktop 9 and SUSE SLES 9 has world-readable permissions, which allows attackers to obtain the rc (RedCarpet) password.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-0646 – ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when lin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0646</guid>
    <pubDate>Sat, 11 Feb 2006 11:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-0646</strong></p>
  <p>ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3655 – Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (nove...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3655</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3655</strong></p>
  <p>Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-2500 – Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2500</guid>
    <pubDate>Mon, 08 Aug 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-2500</strong></p>
  <p>Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-0887 – SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0887</guid>
    <pubDate>Thu, 27 Jan 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-0887</strong></p>
  <p>SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2004-1190 – SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1190</guid>
    <pubDate>Mon, 10 Jan 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2004-1190</strong></p>
  <p>SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associated SCSI devices.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1190">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
