<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – SUSE Multi-Linux Manager (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/suse-manager.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/suse-manager-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – SUSE Multi-Linux Manager (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-53883 – A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53883</guid>
    <pubDate>Thu, 30 Oct 2025 11:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53883</strong></p>
  <p>A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x86_64/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Manager Server LTS 4.3: from ? before 4.3.88-150400.3.113.5.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-46811 – A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46811</guid>
    <pubDate>Wed, 30 Jul 2025 15:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-46811</strong></p>
  <p>A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Serve…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31254 – A Incorrect Default Permissions vulnerability in rmt-server-regsharing service o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31254</guid>
    <pubDate>Tue, 07 Feb 2023 10:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31254</strong></p>
  <p>A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21952 – A Missing Authentication for Critical Function vulnerability in spacewalk-java o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21952</guid>
    <pubDate>Wed, 22 Jun 2022 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21952</strong></p>
  <p>A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25321 – A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25321</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25321</strong></p>
  <p>A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to run arpwatch as to escalate to root upon the next restart of arpwatch. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS arpwatch ve…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18906 – A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18906</guid>
    <pubDate>Wed, 30 Jun 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18906</strong></p>
  <p>A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8028 – A Improper Access Control vulnerability in the configuration of salt of SUSE Lin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8028</guid>
    <pubDate>Thu, 17 Sep 2020 10:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8028</strong></p>
  <p>A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE Manager Server 3.2, SUSE Manager Server 4.0 allows local users to escalate to root on every system managed by SUSE manager. On the managing node itself code can be executed as user salt, potentially al…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8028">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
