SUSE SLES15 Security Update : SUSE Manager Server 4.3 (SUSE-SU-2024:0513-1)

medium Nessus Plugin ID 190653

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2024:0513-1 advisory.

release-notes-susemanager:

- Update to SUSE Manager 4.3.11
* Migrate from RHEL and its clones to SUSE Liberty Linux
* Reboot required indication for non-SUSE distributions
* SSH key rotation for enhanced security
* Configure remote command execution
* End of Debian 10 support
* CVEs fixed:
CVE-2023-32189, CVE-2024-22231, CVE-2024-22232
* Bugs mentioned:
bsc#1170848, bsc#1210911, bsc#1211254, bsc#1211560, bsc#1211912 bsc#1213079, bsc#1213507, bsc#1213738, bsc#1213981, bsc#1214077 bsc#1214791, bsc#1215166, bsc#1215514, bsc#1215769, bsc#1215810 bsc#1215813, bsc#1215982, bsc#1216114, bsc#1216394, bsc#1216437 bsc#1216550, bsc#1216657, bsc#1216753, bsc#1216781, bsc#1216988 bsc#1217069, bsc#1217209, bsc#1217588, bsc#1217784, bsc#1217869 bsc#1218019, bsc#1218074, bsc#1218075, bsc#1218089, bsc#1218094 bsc#1218490, bsc#1218615, bsc#1218669, bsc#1218849, bsc#1219577 bsc#1219850, bsc#1218146

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected release-notes-susemanager package.

See Also

https://bugzilla.suse.com/1170848

https://bugzilla.suse.com/1210911

https://bugzilla.suse.com/1211254

https://bugzilla.suse.com/1211560

https://bugzilla.suse.com/1211912

https://bugzilla.suse.com/1213079

https://bugzilla.suse.com/1213507

https://bugzilla.suse.com/1213738

https://bugzilla.suse.com/1213981

https://bugzilla.suse.com/1214077

https://bugzilla.suse.com/1214791

https://bugzilla.suse.com/1215166

https://bugzilla.suse.com/1215514

https://bugzilla.suse.com/1215769

https://bugzilla.suse.com/1215810

https://bugzilla.suse.com/1215813

https://bugzilla.suse.com/1215982

https://bugzilla.suse.com/1216114

https://bugzilla.suse.com/1216394

https://bugzilla.suse.com/1216437

https://bugzilla.suse.com/1216550

https://bugzilla.suse.com/1216657

https://bugzilla.suse.com/1216753

https://bugzilla.suse.com/1216781

https://bugzilla.suse.com/1216988

https://bugzilla.suse.com/1217069

https://bugzilla.suse.com/1217209

https://bugzilla.suse.com/1217588

https://bugzilla.suse.com/1217784

https://bugzilla.suse.com/1217869

https://bugzilla.suse.com/1218019

https://bugzilla.suse.com/1218074

https://bugzilla.suse.com/1218075

https://bugzilla.suse.com/1218089

https://bugzilla.suse.com/1218094

https://bugzilla.suse.com/1218146

https://bugzilla.suse.com/1218490

https://bugzilla.suse.com/1218615

https://bugzilla.suse.com/1218669

https://bugzilla.suse.com/1218849

https://bugzilla.suse.com/1219577

https://bugzilla.suse.com/1219850

https://www.suse.com/security/cve/CVE-2023-32189

https://www.suse.com/security/cve/CVE-2024-22231

https://www.suse.com/security/cve/CVE-2024-22232

http://www.nessus.org/u?116d3e59

Plugin Details

Severity: Medium

ID: 190653

File Name: suse_SU-2024-0513-1.nasl

Version: 1.3

Type: Local

Agent: unix

Published: 2/17/2024

Updated: 6/25/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, tenable_cloud_security, tenable_self_hosted_container_security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2024-22232

CVSS v3

Risk Factor: High

Base Score: 7.7

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.4

Threat Score: 2.5

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H

CVSS Score Source: CVE-2023-32189

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:release-notes-susemanager, cpe:/o:novell:suse_linux:15

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 2/15/2024

Vulnerability Publication Date: 2/15/2024

Reference Information

CVE: CVE-2023-32189, CVE-2024-22231, CVE-2024-22232

IAVA: 2024-A-0106-S

SuSE: SUSE-SU-2024:0513-1