Known vulnerabilities in SUSE Linux Enterprise Module for Web Scripting 15-SP4

Vendor: SUSE
Version: 15-SP4
Software CPE: cpe:2.3:o:suse:suse_linux_enterprise_module_for_web_scripting:*:*:*:*:*:*:*:*
Total vulnerabilities: 27
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Linux Enterprise Module for Web Scripting version 15-SP4 SUSE Linux Enterprise Module for Web Scripting 15-SP4 is affected by 27 vulnerabilities: 6 high, 19 medium, 2 low Critical High Medium Low

Vulnerabilities (27)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU70788 - Integer overflow
CVE-2022-31631
CWE-190 Medium
No
No
- 07.01.2023 SB2023010702
SB2023010704
SB2023011201
and 21 more
#VU69354 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2022-43548
CWE-350 Medium
No
No
- 15.11.2022 SB2022111599
SB20221115101
SB20221115102
and 47 more
#VU68887 - Integer overflow
CVE-2022-37454
CWE-190 High
Public exploit available
No
- 01.11.2022 SB2022110118
SB2022110119
SB2022110209
and 69 more
#VU68886 - Out-of-bounds read
CVE-2022-31630
CWE-125 Medium
No
No
- 01.11.2022 SB2022110119
SB2022110336
SB2022110814
and 21 more
#VU67850 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-35256
CWE-444 Medium
No
No
- 03.10.2022 SB2022100347
SB2022100401
SB2022100402
and 50 more
#VU67849 - Use of Insufficiently Random Values
CVE-2022-35255
CWE-330 Medium
No
No
- 03.10.2022 SB2022100401
SB2022100402
SB2022100528
and 40 more
#VU67756 - Security Features
CVE-2022-31629
CWE-254 Low
Public exploit available
No
- 29.09.2022 SB2022092960
SB2022093041
SB2022101944
and 49 more
#VU67755 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-31628
CWE-835 Medium
No
No
- 29.09.2022 SB2022092960
SB2022093041
SB2022101944
and 26 more
#VU67166 - Server-Side Request Forgery (SSRF)
CVE-2022-35949
CWE-918 Medium
No
No
- 11.09.2022 SB2022091109
SB2022091110
SB2022091217
and 4 more
#VU67164 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-35948
CWE-93 Medium
No
No
- 11.09.2022 SB2022091109
SB2022091110
SB2022091217
and 4 more
#VU67163 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2022-31150
CWE-93 Medium
No
No
- 11.09.2022 SB2022091108
SB2022091110
SB2022091217
and 2 more
#VU66698 - Exposure of sensitive information to an unauthorized actor
CVE-2022-29244
CWE-200 Medium
No
No
- 22.08.2022 SB2022082252
SB2022082253
SB2022091110
and 15 more
#VU65282 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32215
CWE-444 Medium
No
No
- 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 54 more
#VU65278 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32214
CWE-444 Medium
No
No
- 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 36 more
#VU65275 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32213
CWE-444 Medium
No
No
- 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 55 more
#VU65273 - Improper Check or Handling of Exceptional Conditions
CVE-2022-32212
CWE-703 Medium
No
No
- 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 48 more
#VU62312 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-24828
CWE-78 High
No
No
- 14.04.2022 SB2022041401
SB2022042017
SB2022090517
and 7 more
#VU58331 - Improper input validation
CVE-2021-21707
CWE-20 Medium
No
No
- 23.11.2021 SB2021112317
SB2021112318
SB2022011821
and 21 more
#VU57656 - Out-of-bounds write
CVE-2021-21703
CWE-787 Low
No
No
- 26.10.2021 SB2021102621
SB2021102719
SB2022012745
and 20 more
#VU55101 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-32610
CWE-59 High
No
No
- 20.07.2021 SB2021072062
SB2021072221
SB2021102617
and 12 more


Showing elements 1 - 20 out of 27