A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpensuse Cryptctl
APPOpensuse< 2.4SUSE Linux Enterprise Server
OSSuse12SUSE Manager Server
APPSuse4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same product
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)
CVE-2014-6271CRITICAL9.8⚠ KEVPL ✓same product
ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash
CVE-2013-2465CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność w Java Runtime Environment — ominięcie sandbox w komponencie 2D