Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:3879-1 Critical: Manager and Proxy Server Security Update

suse
Calendar Grey November 4, 2022
Dist Suse Esm H88
Important security updates for SUSE Manager are now available, enhancing integrity, performance, and authentication to protect your systems better
An update that solves three vulnerabilities and has 18 fixes is now available

Summary

This update for release-notes-susemanager, release-notes-susemanager-proxy fixes the following issues: Release notes for SUSE Manager: - Update to SUSE Manager 4.2.10 * Apache exporter has been upgraded to version 0.11.0 * CVEs fixed: CVE-2022-43753, CVE-2022-43754, CVE-2022-31255 * Bugs mentioned: bsc#1195624, bsc#1197724, bsc#1199726, bsc#1200596, bsc#1201059 bsc#1201788, bsc#1202167, bsc#1202729, bsc#1202785, bsc#1203283 bsc#1203406, bsc#1203422, bsc#1203564, bsc#1203599, bsc#1203611 bsc#1203898, bsc#1204146, bsc#1204203, bsc#1195624, bsc#1197724 bsc#1199726, bsc#1200596, bsc#1201059, bsc#1201788, bsc#1202167 bsc#1202729, bsc#1202785, bsc#1203283, bsc#1203406, bsc#1203422 bsc#1203564, bsc#1203599, bsc#1203611, bsc#1203898,

References

#1195624 #1197724 #1199726 #1200596 #1201059

#1201788 #1202167 #1202729 #1202785 #1203283

#1203406 #1203422 #1203564 #1203599 #1203611

#1203898 #1204146 #1204203 #1204543 #1204716

#1204741

Cross- CVE-2022-31255 CVE-2022-43753 CVE-2022-43754

CVSS scores:

CVE-2022-43753 (SUSE): 5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVE-2022-43754 (SUSE): 3 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

Affected Products:

SUSE Manager Proxy 4.2

SUSE Manager Retail Branch Server 4.2

SUSE Manager Server 4.2

https://www.suse.com/security/cve/CVE-2022-31255.html

https://www.suse.com/security/cve/CVE-2022-43753.html

https://www.suse.com/security/cve/CVE-2022-43754.html

https://bugzilla.suse.com/1195624

https://bugzilla.suse.com/1197724

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3879-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here