7.8
CVE-2022-31254
- EPSS 0.03%
- Veröffentlicht 07.02.2023 10:15:52
- Zuletzt bearbeitet 21.11.2024 07:04:13
- Quelle meissner@suse.de
- Teams Watchlist Login
- Unerledigt Login
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10. SUSE Linux Enterprise Server for SAP 15-SP1 rmt-server versions prior to 2.10. SUSE Manager Server 4.1 rmt-server versions prior to 2.10. openSUSE Leap 15.3 rmt-server versions prior to 2.10. openSUSE Leap 15.4 rmt-server versions prior to 2.10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse ≫ Rmt-server Version < 2.10
Suse ≫ Manager Server Version4.1
Opensuse ≫ Leap Version15.3
Opensuse ≫ Leap Version15.4
Suse ≫ Linux Enterprise Server Version15
Suse ≫ Linux Enterprise Server Version15 Updatesp1
Opensuse ≫ Leap Version15.3
Opensuse ≫ Leap Version15.4
Suse ≫ Linux Enterprise Server Version15
Suse ≫ Linux Enterprise Server Version15 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.048 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
meissner@suse.de | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.