Showing 2 vulnerabilities on this page for Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure

Signals CISA KEV Ransomware Nuclei
SUSE vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logs

A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1: from ? before 5.0.14-150600.4.17.1; Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.14-150600.4.17.1; Image SLES15-SP4-Manager-Proxy-4-3-BYOS: from ? before 4.3.33-150400.3.55.2; Image SLES

CWE-256CWE-532Jul 31, 2025
CVSS6.9v4.0EPSS0.233%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint

A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:

CWE-306CWE-862Jul 30, 2025
CVSS9.3v4.0EPSS10.4%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX