CVE-2025-46809

MEDIUM

SUSE - Info Disclosure

Title source: llm
STIX 2.1

Description

A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1: from ? before 5.0.14-150600.4.17.1; Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.14-150600.4.17.1; Image SLES15-SP4-Manager-Proxy-4-3-BYOS: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE: from ? before 4.3.33-150400.3.55.2; SUSE Manager Proxy Module 4.3: from ? before 4.3.33-150400.3.55.2; SUSE Manager Server Module 4.3: from ? before 4.3.33-150400.3.55.2.

Scores

CVSS v3 5.7
EPSS 0.0005
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-256
Status published
Products (13)
SUSE/Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1 ? - 4.3.33-150400.3.55.2
SUSE/Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1 ? - 5.0.14-150600.4.17.1
SUSE/Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 ? - 5.0.14-150600.4.17.1
SUSE/Image SLES15-SP4-Manager-Proxy-4-3-BYOS ? - 4.3.33-150400.3.55.2
SUSE/Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure ? - 4.3.33-150400.3.55.2
SUSE/Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2 ? - 4.3.33-150400.3.55.2
SUSE/Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE ? - 4.3.33-150400.3.55.2
SUSE/Image SLES15-SP4-Manager-Server-4-3-BYOS ? - 4.3.33-150400.3.55.2
SUSE/Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure ? - 4.3.33-150400.3.55.2
SUSE/Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2 ? - 4.3.33-150400.3.55.2
... and 3 more
Published Jul 31, 2025
Tracked Since Feb 18, 2026