First published: Wed Jun 22 2022(Updated: )
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.
Credit: meissner@suse.de meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Manager Server | >=4.1<4.1.46 | |
SUSE Manager Server | >=4.2<4.2.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-21952.
The title of this vulnerability is 'A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2'.
The severity of CVE-2022-21952 is high (7.5).
This vulnerability affects SUSE Manager Server 4.1 versions prior to 4.1.46 and SUSE Manager Server 4.2 versions prior to 4.2.37.
Remote attackers can exploit this vulnerability to exhaust available disk resources, leading to a denial of service (DoS) condition.