SUSE SLES15 : Security update 4.3.16 for Multi-Linux Manager Proxy and Retail Branch Server (SUSE-SU-2025:02475-1)

medium Nessus Plugin ID 242658

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2025:02475-1 advisory.

cobbler:

- Prevent crash during Cobbler startup on NFS environments (bsc#1240666)
- Synchronize cobbler add and sync actions (bsc#1233371)
- Exclude disabled profiles from buildiso gen (bsc#1230908)

grafana-formula:

- Version 4.3.0:
* Added SUSE Linux Enterprise Server 15 SP7 to the supported versions (bsc#1245368)
* Dropped old unsupported SUSE versions from the supported versions list
* Migrated from deprecated Graph panels to new timeseries panels

inter-server-sync:

- Version 0.3.7-0:
* Added SSL signed export and import validation (bsc#1241239)
- Version 0.3.6-0:
* Included /var/log/hub (bsc#1243724)

spacecmd:

- Version 4.3.31-0:
* Improved translation update process

spacewalk-admin:

- Version 4.3.33-0
* Security issues fixed:
- CVE-2025-46809: Do not expose HTTP Proxy password when breaking URL format (bsc#1245005)
* Other bugs fixed:
- Enhance permissions for reposync zypper cache
- Version 4.3.14-0:
* Added support for environment variables in rhn-config-satellite (bsc#1242148)
* mgr-monitoring-ctl: avoid possible errors due to non-ascii characters (bsc#1242030)

spacewalk-backend:

- Version 4.3.32-0
* Removed python3-simplejson use in spacewalk-repo-sync (bsc#1236635)
* Improved translation update process
* Make reposync allow commas as part of HTTP Proxy password (bsc#1243460)
* Removed bootloader linux and initrd files from spacewalk-debug
* Use libzypp's Curl2 backend during reposync (bsc#1245222)

spacewalk-client-tools:

- Version 4.3.23-0
* Improved translation update process

spacewalk-config:

- Version 4.3.16-0
* Allow passing environment variables to rhn-config-satellite (bsc#1242148)

spacewalk-java:

- Version 4.3.87-0
* Security issues fixed:
- CVE-2025-46811: Clean up stale sessions on websocket open (bsc#1246119)
- Version 4.3.86-0:
* Security issues fixed:
- CVE-2025-23393: Filter user input in systems list page (bsc#1240386)
* Other bugs fixed:
- Fixed tooltip text for icons in the patches list (bsc#1234608)
- Fixed openscap audit is running immediately even when scheduled for next days (bsc#1239743)
- Adds calling a highstate in the API for actionchain (bsc#1157520)
- Fixed behavior of `reboot_suggested` or `restart_suggested` by API (bsc#1236910)
- Fixed action chain scheduled within SSM creates no link for the new action chain (bsc#1243825)
- Fixed severity levels missing in API output of errata.getDetails (bsc#1240038)
- Fixed internal server error when accessing groups in activation keys (bsc#1237581)
- Fixed http_proxy_password stored as clear text in /var/log/messages (bsc#1242148)
- Fixed `manage errors` in user-defined pillars (bsc#1230403)
- In CLM live-patching template form, show kernel versions from base product as well (bsc#1239907)
- Improved handling of system list filtering (bsc#1242004)
- Fixed issue preventing OES products from showing up (bsc#1237082)
- Fixed config channels not following priority in highstate (bsc#1237694)
- Improved performance when changing channels on multiple system through SSM (bsc#1239154)
- Fixed package locking for packages not available anymore in the assigned repositories (bsc#1236877)
- Do not show Vendor Advisory link for SL-Micro 6.0 and 6.1 products (bsc#1237770)
- Fixed API namespace for AdminPaygHandler
- Fixed CLM channel name definition (bsc#1239868)
- Fixed XMLRPC API endpoint updateRepoSsl repository property
- Fixed API documentation for system config listFiles (bsc#1245027) + Fixed inconsistency in task schedule deactivation and add activation capability (bsc#1225740)

spacewalk-utils:

- Version 4.3.24-0:
* Removed spacewalk-clone-by-date dependency on python3-simplejson

spacewalk-web:

- Version 4.3.45-0:
* Security issues fixed:
+ CVE-2025-23392, CVE-2025-23393: Filter user input in systems list page (bsc#1239826, bsc#1240386)
* Other bugs fixed:
+ Fix: Filters of type Product Temporary Fix cannot be created (bsc#1238922) + Improved handling of system list filtering (bsc#1242004) + Improved translation update process

subscription-matcher:

- Version 0.40:
* Fixed integer overflow which can cause a division by zero error (bsc#1243239)
- Version 0.39:
* Fixed the wrong matching for 2 Sockets or 2 VMs subscription string (bsc#1238924)
* Fixed logging issues
* Updated runtime dependencies

supportutils-plugin-susemanager:

- Version 4.3.15-0:
* Backported supportutils plugin resource functions, replacing the removed supportutils `scplugin.rc` functions with those provided by `supportconfig.rc`

susemanager:

- Version 4.3.42-0:
* Fixed bootstrap repository definition for SLE 15 SP7 and support only bootstrapping with salt-bundle (bsc#1246788)
- Version 4.3.41-0:
* Improved translation update process

susemanager-build-keys:

- Changed keys to use SHA256 UIDs instead of SHA1 (bsc#1237294, bsc#1236779, jsc#PED-12321)
* Renamed `build-alp-09d9ea69-645b99ce.asc` to `build-alp-09d9ea69.asc`
* Renamed `gpg-pubkey-3fa1d6ce-63c9481c.asc` to `gpg-pubkey-3fa1d6ce.asc`
* Adjusted `suse_ptf_key_2023.asc` and `suse_ptf_key.asc`

susemanager-docs_en:

- SUSE Manager 4.3.16 Update
- Added information about missing monitoring package to Administration Guide (bsc#1191142)
- Added missing script parameters in Installation and Upgrade Guide (bsc#1216187)
- Added reference to the list of supported SCAP profiles (bsc#1213952)
- Extended information in an admonition in Specialized Guides (bsc#1221031)
- Added missing 4505 and 4506 Salt ports in network requirements in Installation and Upgrade Guide
- Removed references to the methods no longer used from Reference Guide (bsc#1209060)
- Fixed Python script in Administration Guide (bsc#1244290)
- Extended troubleshooting section with a reposync example (bsc#1211373)
- Added section about enabling SUSE Manager 4.3 LTS in Installation and Upgrade Guide
- Added missing Task Schedules to the list and updated the Task Schedule page to reflect changesnow only allowing disabling of tasks, not deletion in the Administration Guide
- Added SUSE Linux Enterprise 15 SP7 as a supported client
- Fixed asciidoc menu macro issue with duplicate css class, menu items now display correctly
- Added note about autoyast profiles not having passwords
- Added details about the behavior of the rescheduled failed action (bsc#1244065)
- Updated Network Requirement section to add settings for server configuration behind HTTP OSI level 7 Proxy
- Clarified that NFS with Cobbler is not supported (bsc#1240666)
- Fixed a URL link in Common Workflows Guide (bsc#1242911)
- Documented uptodate action in Common Workflows Guide as background information
- Documented renaming the journal folder when changing machine ID in Administration Guide (bsc#1241286)
- Fixed removing Salt bundle client procedure in Client Configuration Guide
- Added referenced target and remove obsolete section in Common Workflows (bsc#1240842, bsc#1242554)
- Fixed GPG key import command in Administration Guide (bsc#1239102)
- Added java.smtp_server parameter for mail configuration in Administration Guide (bsc#1241490)
- Added system_listeventhistory to spacecmd reference in Reference Guide (bsc#1239604)
- Added links to supported features tables for third party operating systems (bsc#1236810)
- Fixed typo in Installation and Upgrade Guide (bsc#1237403)
- Added note to limit Squid's cache_dir size to 60% of available free space in Installation and Upgrade Guide

susemanager-schema:

- Version 4.3.29-0:
* Fixed typo in OES 24.4 channel definition

susemanager-sls:

- Version 4.3.47-0:
* Change uptodate recurring action to use dist-upgrade instead of upgrade for Debian systems (bsc#1237060)
* Adjust SLS files for SUSE Linux Enterprise SP7 and other systems running higher Python versions
* Optimize SAP module to prevent high IO workload (bsc#1241455)

susemanager-sync-data:

- Version 4.3.24-0:
* Fixed typo in OES 24.4 product definition

How to apply this update:

1. Log in as root user to the SUSE Multi-Linux Manager Server.
2. Stop the Spacewalk service:
`spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update.
4. Start the Spacewalk service:
`spacewalk-service start`

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1157520

https://bugzilla.suse.com/1191142

https://bugzilla.suse.com/1209060

https://bugzilla.suse.com/1211373

https://bugzilla.suse.com/1213952

https://bugzilla.suse.com/1216187

https://bugzilla.suse.com/1221031

https://bugzilla.suse.com/1225740

https://bugzilla.suse.com/1230403

https://bugzilla.suse.com/1230908

https://bugzilla.suse.com/1233371

https://bugzilla.suse.com/1234608

https://bugzilla.suse.com/1236601

https://bugzilla.suse.com/1236635

https://bugzilla.suse.com/1236779

https://bugzilla.suse.com/1236810

https://bugzilla.suse.com/1236877

https://bugzilla.suse.com/1236910

https://bugzilla.suse.com/1237060

https://bugzilla.suse.com/1237082

https://bugzilla.suse.com/1237294

https://bugzilla.suse.com/1237403

https://bugzilla.suse.com/1237581

https://bugzilla.suse.com/1237694

https://bugzilla.suse.com/1237770

https://bugzilla.suse.com/1238922

https://bugzilla.suse.com/1238924

https://bugzilla.suse.com/1239102

https://bugzilla.suse.com/1239154

https://bugzilla.suse.com/1239604

https://bugzilla.suse.com/1239743

https://bugzilla.suse.com/1239826

https://bugzilla.suse.com/1239868

https://bugzilla.suse.com/1239907

https://bugzilla.suse.com/1240038

https://bugzilla.suse.com/1240386

https://bugzilla.suse.com/1240666

https://bugzilla.suse.com/1240842

https://bugzilla.suse.com/1241239

https://bugzilla.suse.com/1241286

https://bugzilla.suse.com/1241455

https://bugzilla.suse.com/1241490

https://bugzilla.suse.com/1242004

https://bugzilla.suse.com/1242030

https://bugzilla.suse.com/1242148

https://bugzilla.suse.com/1242554

https://bugzilla.suse.com/1242911

https://bugzilla.suse.com/1243239

https://bugzilla.suse.com/1243460

https://bugzilla.suse.com/1243724

https://bugzilla.suse.com/1243825

https://bugzilla.suse.com/1244065

https://bugzilla.suse.com/1244290

https://bugzilla.suse.com/1245005

https://bugzilla.suse.com/1245027

https://bugzilla.suse.com/1245222

https://bugzilla.suse.com/1245368

https://bugzilla.suse.com/1246119

https://bugzilla.suse.com/1246788

https://lists.suse.com/pipermail/sle-updates/2025-July/040894.html

https://www.suse.com/security/cve/CVE-2025-23392

https://www.suse.com/security/cve/CVE-2025-23393

https://www.suse.com/security/cve/CVE-2025-46809

https://www.suse.com/security/cve/CVE-2025-46811

Plugin Details

Severity: Medium

ID: 242658

File Name: suse_SU-2025-02475-1.nasl

Version: 1.1

Type: local

Agent: unix

Published: 7/24/2025

Updated: 7/24/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-46811

CVSS v3

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 4.5

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2025-23393

CVSS v4

Risk Factor: Medium

Base Score: 5.6

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2025-23393

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:susemanager-sls, p-cpe:/a:novell:suse_linux:spacewalk-base-minimal-config, p-cpe:/a:novell:suse_linux:subscription-matcher, p-cpe:/a:novell:suse_linux:spacewalk-base-minimal, p-cpe:/a:novell:suse_linux:spacewalk-utils-extras, p-cpe:/a:novell:suse_linux:spacewalk-config, p-cpe:/a:novell:suse_linux:spacewalk-backend-iss-export, p-cpe:/a:novell:suse_linux:spacewalk-java-postgresql, p-cpe:/a:novell:suse_linux:susemanager-schema-utility, p-cpe:/a:novell:suse_linux:python3-spacewalk-client-tools, p-cpe:/a:novell:suse_linux:spacewalk-html, p-cpe:/a:novell:suse_linux:spacewalk-java-config, p-cpe:/a:novell:suse_linux:spacecmd, p-cpe:/a:novell:suse_linux:spacewalk-backend-app, p-cpe:/a:novell:suse_linux:inter-server-sync, p-cpe:/a:novell:suse_linux:susemanager-schema, p-cpe:/a:novell:suse_linux:mgr-daemon, p-cpe:/a:novell:suse_linux:cobbler, p-cpe:/a:novell:suse_linux:spacewalk-backend-tools, p-cpe:/a:novell:suse_linux:susemanager-docs_en, p-cpe:/a:novell:suse_linux:spacewalk-backend-config-files, p-cpe:/a:novell:suse_linux:spacewalk-backend-xml-export-libs, p-cpe:/a:novell:suse_linux:supportutils-plugin-susemanager, p-cpe:/a:novell:suse_linux:spacewalk-admin, p-cpe:/a:novell:suse_linux:grafana-formula, p-cpe:/a:novell:suse_linux:spacewalk-base, p-cpe:/a:novell:suse_linux:susemanager-build-keys, p-cpe:/a:novell:suse_linux:susemanager-tools, p-cpe:/a:novell:suse_linux:spacewalk-proxy-installer, p-cpe:/a:novell:suse_linux:spacewalk-backend-iss, p-cpe:/a:novell:suse_linux:susemanager-tftpsync-recv, p-cpe:/a:novell:suse_linux:spacewalk-backend-applet, p-cpe:/a:novell:suse_linux:spacewalk-backend-server, p-cpe:/a:novell:suse_linux:supportutils-plugin-susemanager-proxy, p-cpe:/a:novell:suse_linux:susemanager-docs_en-pdf, cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:uyuni-config-modules, p-cpe:/a:novell:suse_linux:spacewalk-backend-xmlrpc, p-cpe:/a:novell:suse_linux:spacewalk-client-setup, p-cpe:/a:novell:suse_linux:supportutils-plugin-susemanager-client, p-cpe:/a:novell:suse_linux:spacewalk-taskomatic, p-cpe:/a:novell:suse_linux:python3-spacewalk-client-setup, p-cpe:/a:novell:suse_linux:spacewalk-backend, p-cpe:/a:novell:suse_linux:spacewalk-backend-config-files-common, p-cpe:/a:novell:suse_linux:spacewalk-client-tools, p-cpe:/a:novell:suse_linux:spacewalk-java, p-cpe:/a:novell:suse_linux:spacewalk-utils, p-cpe:/a:novell:suse_linux:uyuni-proxy-systemd-services, p-cpe:/a:novell:suse_linux:susemanager-sync-data, p-cpe:/a:novell:suse_linux:spacewalk-check, p-cpe:/a:novell:suse_linux:susemanager-build-keys-web, p-cpe:/a:novell:suse_linux:spacewalk-backend-config-files-tool, p-cpe:/a:novell:suse_linux:spacewalk-backend-sql, p-cpe:/a:novell:suse_linux:python3-spacewalk-check, p-cpe:/a:novell:suse_linux:spacewalk-java-lib, p-cpe:/a:novell:suse_linux:susemanager, p-cpe:/a:novell:suse_linux:spacewalk-backend-package-push-server, p-cpe:/a:novell:suse_linux:spacewalk-backend-sql-postgresql

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/23/2025

Vulnerability Publication Date: 5/26/2025

Reference Information

CVE: CVE-2025-23392, CVE-2025-23393, CVE-2025-46809, CVE-2025-46811

SuSE: SUSE-SU-2025:02475-1