Known vulnerabilities in SUSE Linux Enterprise Server 12-SP2-LTSS-ERICSSON - page 14

Vendor: SUSE
Version: 12-SP2-LTSS-ERICSSON
Software CPE: cpe:2.3:o:suse:suse_linux_enterprise_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 389
Public exploits: 27
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Linux Enterprise Server version 12-SP2-LTSS-ERICSSON SUSE Linux Enterprise Server 12-SP2-LTSS-ERICSSON is affected by 389 vulnerabilities: 1 critical, 35 high, 221 medium, 132 low Critical High Medium Low

Vulnerabilities (389)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82817 - Incorrect Permission Assignment for Critical Resource
CVE-2022-22941
CWE-732 Medium
No
No
- 07.11.2023 SB2022032942
SB2023110714
SB2022033035
and 21 more
#VU82815 - Authentication Bypass by Capture-replay
CVE-2022-22936
CWE-294 Medium
No
No
- 07.11.2023 SB2022032942
SB2023110714
SB2022033035
and 21 more
#VU82801 - Insufficient Verification of Data Authenticity
CVE-2022-22935
CWE-345 Medium
No
No
- 07.11.2023 SB2022032942
SB2023110714
SB2022033035
and 20 more
#VU82800 - Cryptographic Issues
CVE-2022-22934
CWE-310 Low
No
No
- 07.11.2023 SB2022032942
SB2023110714
SB2022033035
and 21 more
#VU65771 - Information Exposure Through Timing Discrepancy
CVE-2020-25657
CWE-208 Medium
No
No
- 26.07.2022 SB2021011288
SB2022072601
SB2022072602
and 7 more
#VU64922 - Missing Encryption of Sensitive Data
CVE-2022-2097
CWE-311 Low
No
No
- 05.07.2022 SB2022070509
SB2022070522
SB2022070531
and 112 more
#VU64805 - Improper input validation
CVE-2021-43565
CWE-20 Medium
No
No
- 29.06.2022 SB2021120347
SB2022062928
SB2022072127
and 39 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
- 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU63168 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-29217
CWE-327 Medium
No
No
- 13.05.2022 SB2022051319
SB2022071428
SB2022071429
and 12 more
#VU62512 - Improper input validation
CVE-2021-3572
CWE-20 Medium
No
No
- 22.04.2022 SB2022042257
SB2022042259
SB2021071390
and 51 more
#VU62077 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24801
CWE-444 Medium
No
No
- 12.04.2022 SB2022041212
SB2022050231
SB2022050232
and 21 more
#VU61662 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2022-24302
CWE-362 Low
No
No
- 28.03.2022 SB2022032832
SB2022032837
SB2022033014
and 20 more
#VU61600 - Permissions, Privileges, and Access Controls
CVE-2022-24769
CWE-264 Medium
No
No
- 24.03.2022 SB2022032414
SB2022032503
SB2022042141
and 29 more
#VU61471 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0235
CWE-200 Low
No
No
- 20.03.2022 SB2022032001
SB2022032002
SB2022032009
and 35 more
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Public exploit available
No
- 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU60972 - Permissions, Privileges, and Access Controls
CVE-2022-23648
CWE-264 Medium
Public exploit available
No
- 03.03.2022 SB2022030305
SB2022030722
SB2022030725
and 30 more
#VU58229 - Type confusion
CVE-2021-41190
CWE-843 Low
No
No
- 18.11.2021 SB2021111806
SB2021111807
SB2021111809
and 39 more
#VU26356 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-10109
CWE-444 Medium
No
No
- 24.03.2020 SB2020031234
SB2020032419
SB2020043028
and 8 more
#VU25721 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-8130
CWE-78 High
No
No
- 02.03.2020 SB2020030203
SB2020033103
SB2020052720
and 5 more
#VU19388 - Credentials Management
CVE-2018-18074
CWE-255 High
No
No
- 26.07.2019 SB2019072007
SB2019080710
SB2020032626
and 18 more


Showing elements 261 - 280 out of 389