SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CSUSE Studio Extension For System Z
APPSuse1.3SUSE Studio Onsite
APPSuse1.31.3.11.3.21.3.31.3.41.3.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same product
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)
CVE-2014-6271CRITICAL9.8⚠ KEVPL ✓same product
ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash
CVE-2014-9846CRITICAL9.8PL ✓same product
Buffer overflow w ImageMagick — podatność w funkcji ReadRLEImage
CVE-2016-5118CRITICAL9.8PL ✓same product
RCE w GraphicsMagick/ImageMagick — wykonanie kodu przez znak pipe w nazwie pliku
CVE-2016-0718CRITICAL9.8PL ✓same product
Buffer overflow w bibliotece Expat umożliwiający RCE lub DoS