CVE-2025-46809: Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logs
A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container suse/manager/5.0/x8664/proxy-httpd:5.0.5.7.23.1: from ? before 5.0.14-150600.4.17.1; Container suse/manager/5.0/x8664/server:5.0.5.7.30.1: from ? before 5.0.14-150600.4.17.1; Image SLES15-SP4-Manager-Proxy-4-3-BYOS: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE: from ? before 4.3.33-150400.3.55.2; SUSE Manager Proxy Module 4.3: from ? before 4.3.33-150400.3.55.2; SUSE Manager Server Module 4.3: from ? before 4.3.33-150400.3.55.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46809?
CVE-2025-46809 is considered a high-severity vulnerability due to the exposure of sensitive HTTP proxy credentials.
How do I fix CVE-2025-46809?
To remediate CVE-2025-46809, upgrade your SUSE Multi Linux Manager to version 5.0.27-150600.3.33.1 or later.
What systems are affected by CVE-2025-46809?
CVE-2025-46809 affects SUSE Multi Linux Manager versions before 5.0.27-150600.3.33.1 and several SUSE SLES15-SP4-Manager-Server instances with specific versions.
What information is exposed by CVE-2025-46809?
CVE-2025-46809 exposes HTTP proxy credentials, potentially allowing unauthorized access to network resources.
Is there a workaround for CVE-2025-46809?
While upgrading is the recommended solution for CVE-2025-46809, temporarily restricting access to log files may help mitigate the risk.