Skip to main content

Vendor archive

suse CVEs

Beta · best-effort

1,190 CVEs tagged to vendor suse245 Critical, 421 High, 419 Medium, 105 Low, 0 Unrated.

CVE-2023-32186

Published Sep 19, 2023

A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor port (TCP 6443) cause denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22648

Published Jun 1, 2023

A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This wou…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22647

Published Jun 1, 2023

An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43760

Published Jun 1, 2023

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject co…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22651

Published May 4, 2023

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfigura…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-45155

Published Mar 15, 2023

An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the call to the service to delete fi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43759

Published Feb 7, 2023

A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any clu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43758

Published Feb 7, 2023

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add a…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43757

Published Feb 7, 2023

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials ex…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43756

Published Feb 7, 2023

A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote attackers to cause denial of servi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43755

Published Feb 7, 2023

A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This iss…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31249

Published Feb 7, 2023

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote attackers to inject commands i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21953

Published Feb 7, 2023

A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects:…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43754

Published Nov 10, 2022

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-43753

Published Nov 10, 2022

A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31255

Published Nov 10, 2022

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUS…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1931

Published Sep 29, 2022

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before…

CVSS 5.5 · Medium
Showing 26-50 of 1,190 CVEsPage 2 of 48