PT-2022-27025 · Suse · Suse Linux Enterprise Module For Suse Manager Server 4.2+3
Paolo Perego
·
Published
2022-11-04
·
Updated
2022-11-16
·
CVE-2022-43754
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SUSE Linux Enterprise Module for SUSE Manager Server 4.2 versions prior to 4.2.28
SUSE Linux Enterprise Module for SUSE Manager Server 4.3 spacewalk-java versions prior to 4.3.39
SUSE Manager Server 4.2 release-notes-susemanager versions prior to 4.2.10
Description
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') issue allows remote attackers to embed Javascript code via "/rhn/audit/scap/Search.do".
Recommendations
For SUSE Linux Enterprise Module for SUSE Manager Server 4.2, update to version 4.2.28 or later.
For SUSE Linux Enterprise Module for SUSE Manager Server 4.3, update spacewalk-java to version 4.3.39 or later.
For SUSE Manager Server 4.2, update release-notes-susemanager to version 4.2.10 or later.
As a temporary workaround, consider restricting access to the "/rhn/audit/scap/Search.do" endpoint until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse Linux Enterprise Module For Suse Manager Server 4.2
Suse Linux Enterprise Module For Suse Manager Server 4.3
Suse Manager Server 4.2
Suse