7.8
CVE-2022-31254
- EPSS 0.03%
- Published 07.02.2023 10:15:52
- Last modified 21.11.2024 07:04:13
- Source meissner@suse.de
- Teams watchlist Login
- Open Login
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10. SUSE Linux Enterprise Server for SAP 15-SP1 rmt-server versions prior to 2.10. SUSE Manager Server 4.1 rmt-server versions prior to 2.10. openSUSE Leap 15.3 rmt-server versions prior to 2.10. openSUSE Leap 15.4 rmt-server versions prior to 2.10.
Data is provided by the National Vulnerability Database (NVD)
Opensuse ≫ Rmt-server Version < 2.10
Suse ≫ Manager Server Version4.1
Opensuse ≫ Leap Version15.3
Opensuse ≫ Leap Version15.4
Suse ≫ Linux Enterprise Server Version15
Suse ≫ Linux Enterprise Server Version15 Updatesp1
Opensuse ≫ Leap Version15.3
Opensuse ≫ Leap Version15.4
Suse ≫ Linux Enterprise Server Version15
Suse ≫ Linux Enterprise Server Version15 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.048 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
meissner@suse.de | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.