SUSE SLES15: Multi-Linux-Manager-Server-SLE-release / mgradm / etc (SUSE-SU-2025:3839-1)

high Nessus Plugin ID 350288

Synopsis

The remote SUSE host is missing a security update.

Description

The remote SUSE Linux SLES15 host has packages installed that are affected by a vulnerability as referenced in the SUSE- SU-2025:3839-1 advisory.

Multi-Linux-Manager-Server-SLE-release:

- Update for the release packages for fixing the EOL
- Fixed migration issue (bsc#1243486)

server-attestation-image was updated from version 5.1.7 to 5.1.10:

- CVE-2025-53192: Do not use apache-commons-ognl but its successor ognl (bsc#1248252)
- Image rebuilt to the newest version with updated dependencies

server-hub-xmlrpc-api-image was updated from version 5.1.7 to 5.1.9:

- Image rebuilt to the newest version with updated dependencies

server-image was updated from version 5.1.7 to 5.1.9::

- Version 5.1.9
* Install python311-ldap into the server-image (bsc#1245702)
- Version 5.1.8
* Move jmx configuration to a persisting folder (bsc#1244219)

server-migration-14-16-image was updated from version 5.1.7 to 5.1.9:

- Image rebuilt to the newest version with updated dependencies

server-postgresql-image was updated from version 5.1.5 to 5.1.7:

- Image rebuilt to the newest version with updated dependencies

server-saline-image was updated from version 5.1.7 to 5.1.9:

- Image rebuilt to the newest version with updated dependencies

uyuni-tools was updated from version 5.1.18-0 to 5.1.22-0:

- Version 5.1.22-0
* Fixed cobbler config migration to standalone files
* Fixed generated DB certificate subject alternate names
- Version 5.1.21-0
* Removed extraneous quotes when getting the running image (bsc#1249434)
- Version 5.1.20-0
* Added migration for server monitoring configuration (bsc#1247688)
- Version 5.1.19-0
* Added a lowercase version of --logLevel (bsc#1243611)
* Stop executing scripts in temporary folder (bsc#1243704)
* support config: collect podman inspect for hub container (bsc#1245099)
* Use a new dedicated path for Cobbler settings (bsc#1244027)
* Migrated custom auto installation snippets (bsc#1246320)
* Added SUSE Linux Enterprise 15 SP7 to buildin productmap
* Fixed loading product map from mgradm configuration file (bsc#1246068)
* Fixed channel override for distro copy
* Do not use sudo when running as a root user (bsc#1246882)
* Do not require backups to be at the same location for restoring (bsc#1246906)
* Fixed recomputing proxy images when installing a PTF or TEST (bsc#1246553)
* Added mgradm server rename to change the server FQDN (bsc#1229825)
* If no DB SSL CA parameter is given, use the other one (bsc#1245120)
* Made mgradm stop more fault tolerant (bsc#1243331)
* Backup systemd dropin directory too and create if missing
* Added 3rd party SSL options for upgrade and migration scenarios
* Do not consider stderr output of podman as an error (bsc#1247836)
* Restored SELinux contexts for restored backup volumes (bsc#1244127)
* Automatically get up-to-date systemid file on salt based proxy hosts (bsc#1246789)
* Bumped the default image tag to 5.1.1

How to apply this update:

1. Log in as root user to the SUSE Multi-Linux Manager Server.
2. Upgrade mgradm and mgrctl.
3. If you are in a disconnected environment, upgrade the image packages.
4. Reboot the system.
5. Run `mgradm upgrade podman` which will use the default image tags.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1229825

https://bugzilla.suse.com/1243331

https://bugzilla.suse.com/1243486

https://bugzilla.suse.com/1243611

https://bugzilla.suse.com/1243704

https://bugzilla.suse.com/1244027

https://bugzilla.suse.com/1244127

https://bugzilla.suse.com/1244219

https://bugzilla.suse.com/1245099

https://bugzilla.suse.com/1245120

https://bugzilla.suse.com/1245702

https://bugzilla.suse.com/1246068

https://bugzilla.suse.com/1246320

https://bugzilla.suse.com/1246553

https://bugzilla.suse.com/1246789

https://bugzilla.suse.com/1246882

https://bugzilla.suse.com/1246906

https://bugzilla.suse.com/1247688

https://bugzilla.suse.com/1247836

https://bugzilla.suse.com/1248252

https://bugzilla.suse.com/1249434

https://www.suse.com/security/cve/CVE-2025-53192

http://www.nessus.org/u?7fd75cba

Plugin Details

Severity: High

ID: 350288

File Name: suse_SU-2025-3839-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/25/2026

Updated: 9/25/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-53192

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:mgradm-bash-completion, p-cpe:/a:novell:suse_linux:mgradm-lang, p-cpe:/a:novell:suse_linux:mgradm-zsh-completion, p-cpe:/a:novell:suse_linux:mgradm, p-cpe:/a:novell:suse_linux:mgrctl-bash-completion, p-cpe:/a:novell:suse_linux:mgrctl-lang, p-cpe:/a:novell:suse_linux:mgrctl-zsh-completion, p-cpe:/a:novell:suse_linux:mgrctl, p-cpe:/a:novell:suse_linux:multi-linux-manager-server-sle-release, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-saline-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-saline-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-saline-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-saline-image

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/28/2025

Vulnerability Publication Date: 8/18/2025

Reference Information

CVE: CVE-2025-53192

SuSE: SUSE-SU-2025:3839-1