Known vulnerabilities in SUSE Manager Client Tools for SLE 15 - page 4

Vendor: SUSE
Version: 15
Software CPE: cpe:2.3:o:suse:suse_manager_client_tools_for_sle:*:*:*:*:*:*:*:*
Total vulnerabilities: 99
Public exploits: 7
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Manager Client Tools for SLE version 15 SUSE Manager Client Tools for SLE 15 is affected by 99 vulnerabilities: 10 high, 45 medium, 44 low Critical High Medium Low

Vulnerabilities (99)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86612 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22232
CWE-22 Medium
No
No
- 20.02.2024 SB2024022022
SB2024022023
SB2024022024
and 14 more
#VU86611 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22231
CWE-22 Low
No
No
- 20.02.2024 SB2024022022
SB2024022023
SB2024022024
and 13 more
#VU82944 - UNIX Symbolic Link (Symlink) Following
CVE-2023-34049
CWE-61 Low
No
No
- 09.11.2023 SB2023110931
SB2023110932
SB2023110933
and 17 more
#VU79967 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-40577
CWE-79 Low
No
No
- 25.08.2023 SB2023082505
SB2024012403
SB2024021614
and 5 more
#VU78913 - Improper Certificate Validation
CVE-2023-29409
CWE-295 Medium
No
No
- 03.08.2023 SB2023080320
SB2023080321
SB2023080370
and 98 more
#VU69691 - Use of Password Hash Instead of Password for Authentication
CVE-2022-46146
CWE-836 Low
No
No
- 29.11.2022 SB2022112926
SB2022113012
SB2023022044
and 33 more
#VU68390 - Resource exhaustion
CVE-2022-41715
CWE-400 Medium
No
No
- 18.10.2022 SB2022101833
SB2022101834
SB2022102005
and 113 more
#VU65355 - Incorrect Regular Expression
CVE-2020-7753
CWE-185 Medium
No
No
- 15.07.2022 SB2020102724
SB2022071510
SB2023062230
and 12 more
#VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43815
CWE-22 Low
No
No
- 15.06.2022 SB2021121022
SB2022062026
SB2022102094
and 8 more
#VU64034 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3918
CWE-94 High
No
No
- 07.06.2022 SB2021111302
SB2022060836
SB2022071504
and 45 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
- 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
- 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more
#VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43798
CWE-22 High
Public exploit available
Exploited
- 08.12.2021 SB2021120803
SB2022062026
SB2022102094
and 7 more
#VU57967 - Improper input validation
CVE-2021-3807
CWE-20 Medium
No
No
- 05.11.2021 SB2021110513
SB2021112603
SB2022042257
and 51 more
#VU36806 - Key Management Errors
CVE-2016-8614
CWE-320 Medium
No
No
- 31.07.2018 SB2018073121
SB2024050721
SB2016110217
and 7 more
#VU36808 - Command injection
CVE-2016-8628
CWE-77 High
No
No
- 31.07.2018 SB2018073121
SB2024050721
SB2016110217
and 8 more
#VU14157 - Permissions, Privileges, and Access Controls
CVE-2018-10874
CWE-264 Low
No
No
- 31.07.2018 SB2018080113
SB2018073118
SB2019011610
and 10 more
#VU12555 - Information Exposure Through Log Files
CVE-2017-7550
CWE-532 Low
No
No
- 05.03.2018 SB2018030511
SB2017101940
SB2024050718
and 4 more
#VU7411 - Improper input validation
CVE-2016-8647
CWE-20 Low
No
No
- 11.07.2017 SB2017070615
SB2024050718
SB2024050721
and 4 more
#VU6639 - Improper input validation
CVE-2017-7466
CWE-20 Medium
Public exploit available
No
- 17.05.2017 SB2017052310
SB2017052601
SB2017070615
and 22 more


Showing elements 61 - 80 out of 99