CVE-2022-45154

A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise Server 12 supportutils version 3.0.10-95.51.1CWE-312: Cleartext Storage of Sensitive Information and prior versions. SUSE Linux Enterprise Server 15 supportutils version 3.1.21-150000.5.44.1 and prior versions. SUSE Linux Enterprise Server 15 SP3 supportutils version 3.1.21-150300.7.35.15.1 and prior versions.
References
Link Resource
https://bugzilla.suse.com/show_bug.cgi?id=1207598 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:opensuse:supportutils:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:opensuse:supportutils:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:-:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:opensuse:supportutils:*:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp3:*:*:*:*:*:*

History

24 Feb 2023, 18:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Suse
Opensuse
Suse linux Enterprise Server
Opensuse supportutils
CPE cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:15:-:*:*:*:*:*:*
cpe:2.3:a:opensuse:supportutils:*:*:*:*:*:*:*:*
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1207598 - (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1207598 - Exploit, Issue Tracking

15 Feb 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-15 10:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-45154

Mitre link : CVE-2022-45154

CVE.ORG link : CVE-2022-45154


JSON object : View

Products Affected

suse

  • linux_enterprise_server

opensuse

  • supportutils
CWE
CWE-312

Cleartext Storage of Sensitive Information