Vulnerabilities > Suse > Manager Server > 4.2.10

DATE CVE VULNERABILITY TITLE RISK
2023-09-20 CVE-2023-22644 Unspecified vulnerability in Suse Manager Server
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector.
local
low complexity
suse
5.5
2022-06-22 CVE-2022-21952 Unspecified vulnerability in Suse Manager Server
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS.
network
low complexity
suse
7.5
2022-06-22 CVE-2022-31248 Unspecified vulnerability in Suse Manager Server
A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames.
network
low complexity
suse
5.3