First published: Tue Dec 10 2013(Updated: )
SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Suse Lifecycle Management Server | <=1.3 | |
Novell Suse Lifecycle Management Server | =1.0 | |
Novell Suse Lifecycle Management Server | =1.1 | |
Novell Suse Lifecycle Management Server | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.