Known vulnerabilities in SUSE Manager Tools 12-BETA

Vendor: SUSE
Version: 12-BETA
Software CPE: cpe:2.3:o:suse:suse_manager_tools:*:*:*:*:*:*:*:*
Total vulnerabilities: 42
Public exploits: 6
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE Manager Tools version 12-BETA SUSE Manager Tools 12-BETA is affected by 42 vulnerabilities: 6 high, 18 medium, 18 low Critical High Medium Low

Vulnerabilities (42)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU72132 - Improper Authentication
CVE-2022-39229
CWE-287 Low
No
No
- 12.02.2023 SB2023021201
SB2023021202
SB2023021203
and 13 more
#VU72131 - Exposure of sensitive information to an unauthorized actor
CVE-2022-39201
CWE-200 Medium
No
No
- 12.02.2023 SB2023021201
SB2023021202
SB2023021203
and 12 more
#VU72130 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31130
CWE-200 Medium
No
No
- 12.02.2023 SB2023021201
SB2023021202
SB2023021203
and 11 more
#VU72128 - Improper Verification of Cryptographic Signature
CVE-2022-31123
CWE-347 Medium
No
No
- 11.02.2023 SB2023021201
SB2023021202
SB2023021203
and 15 more
#VU69485 - Exposure of sensitive information to an unauthorized actor
CVE-2022-39307
CWE-200 Medium
No
No
- 22.11.2022 SB2022112220
SB2023021202
SB2023021203
and 12 more
#VU69484 - Improper input validation
CVE-2022-39306
CWE-20 Medium
No
No
- 22.11.2022 SB2022112220
SB2023021202
SB2023021203
and 12 more
#VU68336 - UNIX Symbolic Link (Symlink) Following
CVE-2019-3698
CWE-61 Low
No
No
- 14.10.2022 SB2022101445
SB2024051429
SB2024061808
#VU65354 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31097
CWE-79 Low
No
No
- 15.07.2022 SB2022071510
SB2022102094
SB2022102641
and 16 more
#VU65353 - Improper Authentication
CVE-2022-31107
CWE-287 High
No
No
- 15.07.2022 SB2022071510
SB2022072642
SB2022072643
and 21 more
#VU64660 - Improper Authentication
CVE-2022-22967
CWE-287 Low
No
No
- 24.06.2022 SB2022062428
SB2022062430
SB2022062441
and 13 more
#VU64430 - Incorrect Authorization
CVE-2021-41244
CWE-863 Medium
No
No
- 16.06.2022 SB2021111513
SB2022062026
SB2022102094
and 5 more
#VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43815
CWE-22 Low
No
No
- 15.06.2022 SB2021121022
SB2022062026
SB2022102094
and 8 more
#VU64402 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21673
CWE-200 Low
No
No
- 15.06.2022 SB2022061623
SB2022062026
SB2022081215
and 12 more
#VU64397 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21702
CWE-79 Low
No
No
- 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43798
CWE-22 High
Public exploit available
Exploited
- 08.12.2021 SB2021120803
SB2022062026
SB2022102094
and 7 more
#VU57926 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41174
CWE-79 Low
Public exploit available
No
- 03.11.2021 SB2021110312
SB2021110517
SB2022062026
and 4 more
#VU56063 - Memory corruption
CVE-2021-3711
CWE-119 High
No
No
- 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 53 more
#VU54520 - Improper input validation
CVE-2020-14343
CWE-20 High
Public exploit available
No
- 04.07.2021 SB2021070403
SB2021070404
SB2022042259
and 17 more
#VU25823 - Improper input validation
CVE-2020-1747
CWE-20 High
No
No
- 09.03.2020 SB2020030903
SB2020041201
SB2020051129
and 21 more
#VU1344 - UNIX Symbolic Link (Symlink) Following
CVE-2016-9566
CWE-61 Low
Public exploit available
No
- 16.12.2016 SB2016121601
SB2016123102
SB2022101445
and 2 more


Showing elements 1 - 20 out of 42