Known vulnerabilities in SUSE Manager Proxy Module - page 3

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:suse_manager_proxy_module:*:*:*:*:*:*:*:*
Total vulnerabilities: 69
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SUSE Manager Proxy Module SUSE Manager Proxy Module is affected by 69 known vulnerabilities: 7 high, 32 medium, 30 low Critical High Medium Low

Vulnerabilities (69)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU84791 - Information Exposure Through Log Files
CVE-2023-22644
CWE-532 Low
No
No
- 26.12.2023 SB2023122702
SB2023122703
SB2024022748
and 1 more
#VU82944 - UNIX Symbolic Link (Symlink) Following
CVE-2023-34049
CWE-61 Low
No
No
- 09.11.2023 SB2023110931
SB2023110932
SB2023110933
and 17 more
#VU81628 - Out-of-bounds read
CVE-2023-4693
CWE-125 Low
No
No
- 05.10.2023 SB2023100511
SB2023100523
SB2023100703
and 26 more
#VU81627 - Out-of-bounds write
CVE-2023-4692
CWE-787 Low
No
No
- 05.10.2023 SB2023100511
SB2023100523
SB2023100703
and 27 more
#VU80472 - Permissions, Privileges, and Access Controls
CVE-2023-20898
CWE-264 Low
No
No
- 05.09.2023 SB2023090559
SB2023090563
SB2023090601
and 13 more
#VU80471 - Improper input validation
CVE-2023-20897
CWE-20 Medium
No
No
- 05.09.2023 SB2023090559
SB2023090563
SB2023090601
and 14 more
#VU79967 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-40577
CWE-79 Low
No
No
- 25.08.2023 SB2023082505
SB2024012403
SB2024021614
and 5 more
#VU78913 - Improper Certificate Validation
CVE-2023-29409
CWE-295 Medium
No
No
- 03.08.2023 SB2023080320
SB2023080321
SB2023080370
and 98 more
#VU77620 - Exposure of sensitive information to an unauthorized actor
CVE-2023-1387
CWE-200 Medium
No
No
- 22.06.2023 SB2023062227
SB2023062230
SB2023062231
and 7 more
#VU76397 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-28370
CWE-601 Medium
No
No
- 22.05.2023 SB2023052204
SB2023061333
SB2023062257
and 28 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
- 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU68897 - Resource exhaustion
CVE-2022-32149
CWE-400 Medium
No
No
- 01.11.2022 SB2022110139
SB2022110140
SB2022110142
and 68 more
#VU65355 - Incorrect Regular Expression
CVE-2020-7753
CWE-185 Medium
No
No
- 15.07.2022 SB2020102724
SB2022071510
SB2023062230
and 12 more
#VU65354 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31097
CWE-79 Low
No
No
- 15.07.2022 SB2022071510
SB2022102094
SB2022102641
and 16 more
#VU65353 - Improper Authentication
CVE-2022-31107
CWE-287 High
No
No
- 15.07.2022 SB2022071510
SB2022072642
SB2022072643
and 21 more
#VU64034 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3918
CWE-94 High
No
No
- 07.06.2022 SB2021111302
SB2022060836
SB2022071504
and 45 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
- 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
- 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more
#VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43798
CWE-22 High
Available
Exploited
- 08.12.2021 SB2021120803
SB2022062026
SB2022102094
and 7 more
#VU57967 - Improper input validation
CVE-2021-3807
CWE-20 Medium
No
No
- 05.11.2021 SB2021110513
SB2021112603
SB2022042257
and 51 more


Showing elements 41 - 60 out of 69