CVE-2022-45153: saphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.sls
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. SUSE Linux Enterprise Server for SAP 12-SP5 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. openSUSE Leap 15.4 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-45153?
CVE-2022-45153 is an Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5, and openSUSE Leap 15.4.
What is the severity of CVE-2022-45153?
The severity of CVE-2022-45153 is high with a CVSS score of 7.8.
How does CVE-2022-45153 work?
CVE-2022-45153 allows local attackers to escalate their privileges to root by manipulating the sudo configuration created by the saphanabootstrap-formula.
Which software versions are affected by CVE-2022-45153?
CVE-2022-45153 affects SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5, and openSUSE Leap 15.4.
Is there a fix for CVE-2022-45153?
Yes, a fix is available for CVE-2022-45153. Please refer to the official documentation or contact your software vendor for the patch or update.