VendorsSUSEmanager_serverall versions
Vulnerabilities

SUSE Manager Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2019-18906
cryptctl: client side password hashing is equivalent to clear text password storage
Published 2021-06-30 · Modified
9.8EPSS 0.011
CVE-2023-22644
JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
Published 2023-09-20 · Modified
9.4EPSS 0.005
CVE-2020-8028
salt-api is accessible to every user on SUSE Manager Server
Published 2020-09-17 · Modified
9.3EPSS 0.004
CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
Published 2026-04-22 · Analyzed
7.8KEVEPSS 0.999
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Published 2022-01-28 · Analyzed
7.8KEV1 PoCEPSS 0.949
CVE-2022-27239
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Published 2022-04-27 · Modified
7.8EPSS 0.006
CVE-2021-25321
arpwatch: Local privilege escalation from runtime user to root
Published 2021-06-30 · Modified
7.8EPSS 0.004
CVE-2022-31254
rmt-server-pubcloud allows to escalate from user _rmt to root
Published 2023-02-07 · Modified
7.8EPSS 0.002
CVE-2023-29552
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Published 2023-04-25 · Analyzed
7.5KEVEPSS 0.659
CVE-2022-21952
SUMA unauthenticated remote DoS via resource exhaustion
Published 2022-06-22 · Analyzed
7.5EPSS 0.015
CVE-2022-43754
SUMA/UYUNI reflected cross site scripting in /rhn/audit/scap/Search.do
Published 2022-11-10 · Modified
5.4EPSS 0.004
CVE-2022-31248
SUMA user enumeration via weak error message
Published 2022-06-22 · Modified
5.3EPSS 0.010
CVE-2014-3595
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.
Published 2014-09-22 · Modified
4.3EPSS 0.018
CVE-2014-3654
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3) admin/multiorg/OrgUsers.do.
Published 2014-11-03 · Modified
4.3EPSS 0.018
CVE-2022-43753
SUMA/UYUNI arbitrary file disclosure vulnerability in ScapResultDownload
Published 2022-11-10 · Modified
4.3EPSS 0.008
CVE-2022-31255
SUMA/UYUNI directory path traversal vulnerability in CobblerSnipperViewAction
Published 2022-11-10 · Modified
4.3EPSS 0.007
CVE-2021-25317
cups: ownership of /var/log/cups allows the lp user to create files as root
Published 2021-05-05 · Modified
3.3EPSS 0.003