PT-2014-2703 · Suse · Suse Studio Onsite+1
Published
2014-02-26
·
Updated
2014-03-10
·
CVE-2013-3712
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SUSE Studio Onsite versions 1.3.x through 1.3.5
SUSE Studio Extension for System z version 1.3
Description
The issue is related to the use of "static" secret tokens, which has an unspecified impact and vectors.
Recommendations
For SUSE Studio Onsite versions 1.3.x through 1.3.5, update to version 1.3.6 or later.
For SUSE Studio Extension for System z version 1.3, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Studio Extension For System Z
Suse Studio Onsite