SUSE SLES15 Security Update : SUSE Manager Server 4.3 (SUSE-SU-2024:4007-1)

medium Nessus Plugin ID 212528

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2024:4007-1 advisory.

release-notes-susemanager:

- Update to SUSE Manager 4.3.14
* Ubuntu 24.04 support as client
* Product migration from RHEL and Clones to SUSE Liberty Linux
* POS image templates now produce compressed images
* Date format for API endpoints has been changed to ISO-8601 format
* Security issues fixed:
CVE-2024-47533, CVE-2024-49502, CVE-2024-49503
* Bugs mentioned:
bsc#1146701, bsc#1211899, bsc#1212985, bsc#1217003, bsc#1217338 bsc#1217978, bsc#1218090, bsc#1219450, bsc#1219645, bsc#1219887 bsc#1221435, bsc#1221505, bsc#1223312, bsc#1223988, bsc#1224108 bsc#1224209, bsc#1225603, bsc#1225619, bsc#1225960, bsc#1226090 bsc#1226439, bsc#1226461, bsc#1226478, bsc#1226687, bsc#1226917 bsc#1227133, bsc#1227334, bsc#1227406, bsc#1227526, bsc#1227543 bsc#1227599, bsc#1227606, bsc#1227746, bsc#1228036, bsc#1228101 bsc#1228130, bsc#1228147, bsc#1228286, bsc#1228326, bsc#1228345 bsc#1228412, bsc#1228545, bsc#1228638, bsc#1228851, bsc#1228945 bsc#1229079, bsc#1229178, bsc#1229260, bsc#1229339, bsc#1231332 bsc#1231852, bsc#1231922, bsc#1231900

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected release-notes-susemanager package.

See Also

https://bugzilla.suse.com/1231332

https://www.suse.com/security/cve/CVE-2024-47533

https://bugzilla.suse.com/1146701

https://bugzilla.suse.com/1211899

https://bugzilla.suse.com/1212985

https://bugzilla.suse.com/1217003

https://bugzilla.suse.com/1217338

https://bugzilla.suse.com/1217978

https://bugzilla.suse.com/1218090

https://bugzilla.suse.com/1219450

https://bugzilla.suse.com/1219645

https://bugzilla.suse.com/1219887

https://bugzilla.suse.com/1221435

https://bugzilla.suse.com/1221505

https://bugzilla.suse.com/1223312

https://bugzilla.suse.com/1223988

https://bugzilla.suse.com/1224108

https://bugzilla.suse.com/1224209

https://bugzilla.suse.com/1225603

https://bugzilla.suse.com/1225619

https://bugzilla.suse.com/1225960

https://bugzilla.suse.com/1226090

https://bugzilla.suse.com/1226439

https://bugzilla.suse.com/1226461

https://bugzilla.suse.com/1226478

https://bugzilla.suse.com/1226687

https://bugzilla.suse.com/1226917

https://bugzilla.suse.com/1227133

https://bugzilla.suse.com/1227334

https://bugzilla.suse.com/1227406

https://bugzilla.suse.com/1227526

https://bugzilla.suse.com/1227543

https://bugzilla.suse.com/1227599

https://bugzilla.suse.com/1227606

https://bugzilla.suse.com/1227746

https://bugzilla.suse.com/1228036

https://bugzilla.suse.com/1228101

https://bugzilla.suse.com/1228130

https://bugzilla.suse.com/1228147

https://bugzilla.suse.com/1228286

https://bugzilla.suse.com/1228326

https://bugzilla.suse.com/1228345

https://bugzilla.suse.com/1228412

https://bugzilla.suse.com/1228545

https://bugzilla.suse.com/1228638

https://bugzilla.suse.com/1228851

https://bugzilla.suse.com/1228945

https://bugzilla.suse.com/1229079

https://bugzilla.suse.com/1229178

https://bugzilla.suse.com/1229260

https://bugzilla.suse.com/1229339

https://bugzilla.suse.com/1231852

https://bugzilla.suse.com/1231900

https://bugzilla.suse.com/1231922

https://www.suse.com/security/cve/CVE-2024-49502

https://www.suse.com/security/cve/CVE-2024-49503

http://www.nessus.org/u?2a77d7d2

Plugin Details

Severity: Medium

ID: 212528

File Name: suse_SU-2024-4007-1.nasl

Version: 1.1

Type: local

Agent: unix

Published: 12/12/2024

Updated: 12/12/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-47533

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 4.6

Threat Score: 1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2024-49503

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:release-notes-susemanager, cpe:/o:novell:suse_linux:15

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 11/18/2024

Vulnerability Publication Date: 11/17/2024

Reference Information

CVE: CVE-2024-47533, CVE-2024-49502, CVE-2024-49503

SuSE: SUSE-SU-2024:4007-1