Vulnerabilidades em SUSE

229 resultados
Análise Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2019-3683HIGHkeystone_json_assignment backend granted access to any project for users in user-project-map.jsonEPSS 0.9%CVE-2024-22033MEDIUMobs-service-download_url is vulnerable to argument injectionEPSS 0.9%CVE-2011-3172MEDIUMunix2_chkpwd do not check for a valid accountEPSS 0.9%CVE-2021-36784HIGHPrivilege escalation for users with create/update permissions in Global RolesEPSS 0.9%CVE-2011-4190MEDIUMMissing verification of host key for kdump serverEPSS 0.9%CVE-2020-8022HIGHUser-writeable configuration file /usr/lib/tmpfiles.d/tomcat.conf allows for escalation of priviligesEPSS 0.9%CVE-2015-0796MEDIUMopen build service source server symlink exploitation via source patchEPSS 0.8%CVE-2024-22036CRITICALRancher Remote Code Execution via Cluster/Node DriversEPSS 0.8%CVE-2023-22651CRITICALImproper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admissioEPSS 0.8%CVE-2022-43753MEDIUMSUMA/UYUNI arbitrary file disclosure vulnerability in ScapResultDownloadEPSS 0.8%CVE-2021-36783CRITICALRancher: Failure to properly sanitize credentials in cluster template answersEPSS 0.8%CVE-2021-36778HIGHExposure of repository credentials to external third-party sourcesEPSS 0.8%CVE-2019-18905MEDIUMDeprecated functionality in autoyast2 automatically imports gpg keys without checking themEPSS 0.7%CVE-2022-31255MEDIUMSUMA/UYUNI directory path traversal vulnerability in CobblerSnipperViewActionEPSS 0.7%CVE-2023-32187HIGHAn Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supEPSS 0.7%CVE-2023-22647CRITICALAn Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate KEPSS 0.7%CVE-2022-43760HIGHAn Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some hEPSS 0.7%CVE-2019-3684MEDIUMsusemanager installer creates world-readable swap filesEPSS 0.7%CVE-2023-32186HIGHA Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supEPSS 0.7%CVE-2022-43756MEDIUMRancher/Wrangler: Denial of service when processing Git credentialsEPSS 0.7%