PT-2014-2703 · Suse · Suse Studio Onsite+1
Publicado
2014-02-26
·
Atualizado
2014-03-10
·
CVE-2013-3712
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Studio Onsite versions 1.3.x through 1.3.5
SUSE Studio Extension for System z version 1.3
Description
The issue is related to the use of "static" secret tokens, which has an unspecified impact and vectors.
Recommendations
For SUSE Studio Onsite versions 1.3.x through 1.3.5, update to version 1.3.6 or later.
For SUSE Studio Extension for System z version 1.3, at the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse Studio Extension For System Z
Suse Studio Onsite