CVE-2014-7811
SUSE Manager 1.7 for SLE 11 SP2,SUSE Manager Server
CVE-2014-7811, security advisory, novell, suse linux, suse, security, cve

CVE-2014-7811

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2014-7811 at MITRE

Description

Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the REST API.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database SUSE
Base Score 3.5 4.3
Vector AV:N/AC:M/Au:S/C:N/I:P/A:N AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network Network
Access Complexity Medium Medium
Authentication Single None
Confidentiality Impact None None
Integrity Impact Partial Partial
Availability Impact None None
SUSE Bugzilla entries: 902915 [RESOLVED], 912886 [RESOLVED], 922740 [RESOLVED / FIXED], 969911 [RESOLVED / DUPLICATE]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Manager 1.7
  • sm-ncc-sync-data >= 1.7.21-0.5.1
  • smdba >= 1.5-0.6.2.1
  • spacecmd >= 1.7.7.12-0.5.1
  • spacewalk-backend >= 1.7.38.34-0.5.1
  • spacewalk-backend-app >= 1.7.38.34-0.5.1
  • spacewalk-backend-applet >= 1.7.38.34-0.5.1
  • spacewalk-backend-config-files >= 1.7.38.34-0.5.1
  • spacewalk-backend-config-files-common >= 1.7.38.34-0.5.1
  • spacewalk-backend-config-files-tool >= 1.7.38.34-0.5.1
  • spacewalk-backend-iss >= 1.7.38.34-0.5.1
  • spacewalk-backend-iss-export >= 1.7.38.34-0.5.1
  • spacewalk-backend-libs >= 1.7.38.34-0.5.1
  • spacewalk-backend-package-push-server >= 1.7.38.34-0.5.1
  • spacewalk-backend-server >= 1.7.38.34-0.5.1
  • spacewalk-backend-sql >= 1.7.38.34-0.5.1
  • spacewalk-backend-sql-oracle >= 1.7.38.34-0.5.1
  • spacewalk-backend-sql-postgresql >= 1.7.38.34-0.5.1
  • spacewalk-backend-tools >= 1.7.38.34-0.5.1
  • spacewalk-backend-xml-export-libs >= 1.7.38.34-0.5.1
  • spacewalk-backend-xmlrpc >= 1.7.38.34-0.5.1
  • spacewalk-backend-xp >= 1.7.38.34-0.5.1
  • spacewalk-branding >= 1.7.1.13-0.5.1
  • spacewalk-java >= 1.7.54.34-0.5.1
  • spacewalk-java-config >= 1.7.54.34-0.5.1
  • spacewalk-java-lib >= 1.7.54.34-0.5.1
  • spacewalk-java-oracle >= 1.7.54.34-0.5.1
  • spacewalk-java-postgresql >= 1.7.54.34-0.5.1
  • spacewalk-setup >= 1.7.9.12-0.5.1
  • spacewalk-taskomatic >= 1.7.54.34-0.5.1
  • susemanager >= 1.7.30-0.5.2
  • susemanager-schema >= 1.7.56.24-0.7.1
  • susemanager-tools >= 1.7.30-0.5.2
Patchnames:
sleman17sp2-sm-ncc-sync-data
SUSE Manager 2.1
  • apache2-mod_wsgi >= 3.3-5.7.17
  • auditlog-keeper >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-rdbms >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-spacewalk-validator >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-syslog >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-xmlout >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • cobbler >= 2.2.2-0.54.9
  • google-gson >= 2.2.4-0.7.52
  • libyaml-0-2 >= 0.1.3-0.10.16.11
  • oracle-config >= 1.1-0.10.10.16
  • osa-dispatcher >= 5.11.33.7-0.7.16
  • perl-Class-Singleton >= 1.4-4.13.38
  • perl-NOCpulse-Object >= 1.26.13.2-0.7.13
  • perl-Satcon >= 1.20.2-0.7.6
  • perl-auditlog-keeper-client >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • postgresql91-pltcl >= 9.1.15-0.3.1
  • pxe-default-image >= 0.1-0.20.56
  • python-enum34 >= 1.0-0.7.33
  • python-gzipstream >= 1.10.2.2-0.7.6
  • rhn-custom-info >= 5.4.22.6-0.7.13
  • rhnlib >= 2.5.69.6-0.7.6
  • rhnmd >= 5.3.18.4-0.7.15
  • rhnpush >= 5.5.71.7-0.7.16
  • sm-ncc-sync-data >= 2.1.9-0.7.6
  • smdba >= 1.5.1-0.7.6
  • spacecmd >= 2.1.25.7-0.7.9
  • spacewalk-admin >= 2.1.2.4-0.7.6
  • spacewalk-backend >= 2.1.55.15-0.7.11
  • spacewalk-backend-app >= 2.1.55.15-0.7.11
  • spacewalk-backend-applet >= 2.1.55.15-0.7.11
  • spacewalk-backend-config-files >= 2.1.55.15-0.7.11
  • spacewalk-backend-config-files-common >= 2.1.55.15-0.7.11
  • spacewalk-backend-config-files-tool >= 2.1.55.15-0.7.11
  • spacewalk-backend-iss >= 2.1.55.15-0.7.11
  • spacewalk-backend-iss-export >= 2.1.55.15-0.7.11
  • spacewalk-backend-libs >= 2.1.55.15-0.7.11
  • spacewalk-backend-package-push-server >= 2.1.55.15-0.7.11
  • spacewalk-backend-server >= 2.1.55.15-0.7.11
  • spacewalk-backend-sql >= 2.1.55.15-0.7.11
  • spacewalk-backend-sql-oracle >= 2.1.55.15-0.7.11
  • spacewalk-backend-sql-postgresql >= 2.1.55.15-0.7.11
  • spacewalk-backend-tools >= 2.1.55.15-0.7.11
  • spacewalk-backend-xml-export-libs >= 2.1.55.15-0.7.11
  • spacewalk-backend-xmlrpc >= 2.1.55.15-0.7.11
  • spacewalk-base >= 2.1.60.12-0.7.7
  • spacewalk-base-minimal >= 2.1.60.12-0.7.7
  • spacewalk-base-minimal-config >= 2.1.60.12-0.7.7
  • spacewalk-branding >= 2.1.33.10-0.7.16
  • spacewalk-certs-tools >= 2.1.6.5-0.7.10
  • spacewalk-check >= 2.1.16.6-0.7.9
  • spacewalk-client-setup >= 2.1.16.6-0.7.9
  • spacewalk-client-tools >= 2.1.16.6-0.7.9
  • spacewalk-config >= 2.1.5.4-0.7.15
  • spacewalk-doc-indexes >= 2.1.2.3-0.7.26
  • spacewalk-grail >= 2.1.60.12-0.7.7
  • spacewalk-html >= 2.1.60.12-0.7.7
  • spacewalk-java >= 2.1.165.14-0.7.16
  • spacewalk-java-config >= 2.1.165.14-0.7.16
  • spacewalk-java-lib >= 2.1.165.14-0.7.16
  • spacewalk-java-oracle >= 2.1.165.14-0.7.16
  • spacewalk-java-postgresql >= 2.1.165.14-0.7.16
  • spacewalk-pxt >= 2.1.60.12-0.7.7
  • spacewalk-reports >= 2.1.14.8-0.7.10
  • spacewalk-search >= 2.1.14.6-0.7.18
  • spacewalk-setup >= 2.1.14.9-0.7.6
  • spacewalk-setup-jabberd >= 2.1.0.2-0.7.6
  • spacewalk-sniglets >= 2.1.60.12-0.7.7
  • spacewalk-taskomatic >= 2.1.165.14-0.7.16
  • spacewalk-utils >= 2.1.27.12-0.7.25
  • spacewalksd >= 5.0.14.6-0.7.15
  • struts >= 1.2.9-162.33.22
  • supportutils-plugin-susemanager >= 1.0.3-0.5.5
  • supportutils-plugin-susemanager-client >= 1.0.4-0.5.5
  • suseRegisterInfo >= 2.1.9-0.7.29
  • susemanager >= 2.1.17-0.7.11
  • susemanager-client-config_en-pdf >= 2.1-0.15.24
  • susemanager-install_en-pdf >= 2.1-0.15.24
  • susemanager-jsp_en >= 2.1-0.15.23
  • susemanager-manuals_en >= 2.1-0.15.24
  • susemanager-proxy-quick_en-pdf >= 2.1-0.15.24
  • susemanager-reference_en-pdf >= 2.1-0.15.24
  • susemanager-schema >= 2.1.50.11-0.7.8
  • susemanager-sync-data >= 2.1.5-0.7.6
  • susemanager-tools >= 2.1.17-0.7.11
  • susemanager-user_en-pdf >= 2.1-0.15.24
  • tanukiwrapper >= 3.2.3-0.10.12
  • yum >= 3.2.29-0.19.30
  • yum-common >= 3.2.29-0.19.30
  • zypp-plugin-spacewalk >= 0.9.8-0.15.51
Patchnames:
sleman21-suse-manager-201503
sleman21-suse-manager-21-201502
SUSE Manager Server
  • apache2-mod_wsgi >= 3.3-5.7.17
  • auditlog-keeper >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-rdbms >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-spacewalk-validator >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-syslog >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • auditlog-keeper-xmlout >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • cobbler >= 2.2.2-0.54.9
  • google-gson >= 2.2.4-0.7.52
  • libyaml-0-2 >= 0.1.3-0.10.16.11
  • oracle-config >= 1.1-0.10.10.16
  • osa-dispatcher >= 5.11.33.7-0.7.16
  • perl-Class-Singleton >= 1.4-4.13.38
  • perl-NOCpulse-Object >= 1.26.13.2-0.7.13
  • perl-Satcon >= 1.20.2-0.7.6
  • perl-auditlog-keeper-client >= 0.2.3+git.1417708457.eabd1a9-0.7.58
  • pxe-default-image >= 0.1-0.20.56
  • python-enum34 >= 1.0-0.7.33
  • python-gzipstream >= 1.10.2.2-0.7.6
  • rhn-custom-info >= 5.4.22.6-0.7.13
  • rhnlib >= 2.5.69.6-0.7.6
  • rhnmd >= 5.3.18.4-0.7.15
  • rhnpush >= 5.5.71.7-0.7.16
  • sm-ncc-sync-data >= 2.1.9-0.7.6
  • smdba >= 1.5.1-0.7.6
  • spacecmd >= 2.1.25.7-0.7.9
  • spacewalk-admin >= 2.1.2.4-0.7.6
  • spacewalk-backend >= 2.1.55.15-0.7.11
  • spacewalk-backend-app >= 2.1.55.15-0.7.11
  • spacewalk-backend-applet >= 2.1.55.15-0.7.11
  • spacewalk-backend-config-files >= 2.1.55.15-0.7.11
  • spacewalk-backend-config-files-common >= 2.1.55.15-0.7.11
  • spacewalk-backend-config-files-tool >= 2.1.55.15-0.7.11
  • spacewalk-backend-iss >= 2.1.55.15-0.7.11
  • spacewalk-backend-iss-export >= 2.1.55.15-0.7.11
  • spacewalk-backend-libs >= 2.1.55.15-0.7.11
  • spacewalk-backend-package-push-server >= 2.1.55.15-0.7.11
  • spacewalk-backend-server >= 2.1.55.15-0.7.11
  • spacewalk-backend-sql >= 2.1.55.15-0.7.11
  • spacewalk-backend-sql-oracle >= 2.1.55.15-0.7.11
  • spacewalk-backend-sql-postgresql >= 2.1.55.15-0.7.11
  • spacewalk-backend-tools >= 2.1.55.15-0.7.11
  • spacewalk-backend-xml-export-libs >= 2.1.55.15-0.7.11
  • spacewalk-backend-xmlrpc >= 2.1.55.15-0.7.11
  • spacewalk-base >= 2.1.60.12-0.7.7
  • spacewalk-base-minimal >= 2.1.60.12-0.7.7
  • spacewalk-base-minimal-config >= 2.1.60.12-0.7.7
  • spacewalk-branding >= 2.1.33.10-0.7.16
  • spacewalk-certs-tools >= 2.1.6.5-0.7.10
  • spacewalk-check >= 2.1.16.6-0.7.9
  • spacewalk-client-setup >= 2.1.16.6-0.7.9
  • spacewalk-client-tools >= 2.1.16.6-0.7.9
  • spacewalk-config >= 2.1.5.4-0.7.15
  • spacewalk-doc-indexes >= 2.1.2.3-0.7.26
  • spacewalk-grail >= 2.1.60.12-0.7.7
  • spacewalk-html >= 2.1.60.12-0.7.7
  • spacewalk-java >= 2.1.165.14-0.7.16
  • spacewalk-java-config >= 2.1.165.14-0.7.16
  • spacewalk-java-lib >= 2.1.165.14-0.7.16
  • spacewalk-java-oracle >= 2.1.165.14-0.7.16
  • spacewalk-java-postgresql >= 2.1.165.14-0.7.16
  • spacewalk-pxt >= 2.1.60.12-0.7.7
  • spacewalk-reports >= 2.1.14.8-0.7.10
  • spacewalk-search >= 2.1.14.6-0.7.18
  • spacewalk-setup >= 2.1.14.9-0.7.6
  • spacewalk-setup-jabberd >= 2.1.0.2-0.7.6
  • spacewalk-sniglets >= 2.1.60.12-0.7.7
  • spacewalk-taskomatic >= 2.1.165.14-0.7.16
  • spacewalk-utils >= 2.1.27.12-0.7.25
  • spacewalksd >= 5.0.14.6-0.7.15
  • struts >= 1.2.9-162.33.22
  • suseRegisterInfo >= 2.1.9-0.7.29
  • susemanager >= 2.1.17-0.7.11
  • susemanager-client-config_en-pdf >= 2.1-0.15.24
  • susemanager-install_en-pdf >= 2.1-0.15.24
  • susemanager-jsp_en >= 2.1-0.15.23
  • susemanager-manuals_en >= 2.1-0.15.24
  • susemanager-proxy-quick_en-pdf >= 2.1-0.15.24
  • susemanager-reference_en-pdf >= 2.1-0.15.24
  • susemanager-schema >= 2.1.50.11-0.7.8
  • susemanager-sync-data >= 2.1.5-0.7.6
  • susemanager-tools >= 2.1.17-0.7.11
  • susemanager-user_en-pdf >= 2.1-0.15.24
  • tanukiwrapper >= 3.2.3-0.10.12
  • yum >= 3.2.29-0.19.30
  • yum-common >= 3.2.29-0.19.30
  • zypp-plugin-spacewalk >= 0.9.8-0.15.51
Builds
SAT Patch Nr: 10396
SUSE Manager Server
  • cobbler >= 2.2.2-0.54.2
  • osa-dispatcher >= 5.11.33.7-0.7.3
  • perl-NOCpulse-Object >= 1.26.13.2-0.7.4
  • perl-Satcon >= 1.20.2-0.7.1
  • python-gzipstream >= 1.10.2.2-0.7.1
  • rhn-custom-info >= 5.4.22.6-0.7.4
  • rhnlib >= 2.5.69.6-0.7.1
  • rhnmd >= 5.3.18.4-0.7.3
  • rhnpush >= 5.5.71.7-0.7.5
  • sm-ncc-sync-data >= 2.1.9-0.7.1
  • smdba >= 1.5.1-0.7.1
  • spacewalk-admin >= 2.1.2.4-0.7.1
  • spacewalk-backend >= 2.1.55.15-0.7.3
  • spacewalk-backend-app >= 2.1.55.15-0.7.3
  • spacewalk-backend-applet >= 2.1.55.15-0.7.3
  • spacewalk-backend-config-files >= 2.1.55.15-0.7.3
  • spacewalk-backend-config-files-common >= 2.1.55.15-0.7.3
  • spacewalk-backend-config-files-tool >= 2.1.55.15-0.7.3
  • spacewalk-backend-iss >= 2.1.55.15-0.7.3
  • spacewalk-backend-iss-export >= 2.1.55.15-0.7.3
  • spacewalk-backend-libs >= 2.1.55.15-0.7.3
  • spacewalk-backend-package-push-server >= 2.1.55.15-0.7.3
  • spacewalk-backend-server >= 2.1.55.15-0.7.3
  • spacewalk-backend-sql >= 2.1.55.15-0.7.3
  • spacewalk-backend-sql-oracle >= 2.1.55.15-0.7.3
  • spacewalk-backend-sql-postgresql >= 2.1.55.15-0.7.3
  • spacewalk-backend-tools >= 2.1.55.15-0.7.3
  • spacewalk-backend-xml-export-libs >= 2.1.55.15-0.7.3
  • spacewalk-backend-xmlrpc >= 2.1.55.15-0.7.3
  • spacewalk-base >= 2.1.60.12-0.7.3
  • spacewalk-base-minimal >= 2.1.60.12-0.7.3
  • spacewalk-base-minimal-config >= 2.1.60.12-0.7.3
  • spacewalk-branding >= 2.1.33.10-0.7.4
  • spacewalk-certs-tools >= 2.1.6.5-0.7.2
  • spacewalk-check >= 2.1.16.6-0.7.1
  • spacewalk-client-setup >= 2.1.16.6-0.7.1
  • spacewalk-client-tools >= 2.1.16.6-0.7.1
  • spacewalk-config >= 2.1.5.4-0.7.5
  • spacewalk-doc-indexes >= 2.1.2.3-0.7.5
  • spacewalk-grail >= 2.1.60.12-0.7.3
  • spacewalk-html >= 2.1.60.12-0.7.3
  • spacewalk-java >= 2.1.165.14-0.7.4
  • spacewalk-java-config >= 2.1.165.14-0.7.4
  • spacewalk-java-lib >= 2.1.165.14-0.7.4
  • spacewalk-java-oracle >= 2.1.165.14-0.7.4
  • spacewalk-java-postgresql >= 2.1.165.14-0.7.4
  • spacewalk-pxt >= 2.1.60.12-0.7.3
  • spacewalk-reports >= 2.1.14.8-0.7.2
  • spacewalk-search >= 2.1.14.6-0.7.4
  • spacewalk-setup >= 2.1.14.9-0.7.1
  • spacewalk-setup-jabberd >= 2.1.0.2-0.7.1
  • spacewalk-sniglets >= 2.1.60.12-0.7.3
  • spacewalk-taskomatic >= 2.1.165.14-0.7.4
  • spacewalk-utils >= 2.1.27.12-0.7.9
  • spacewalksd >= 5.0.14.6-0.7.3
  • supportutils-plugin-susemanager >= 1.0.3-0.5.1
  • supportutils-plugin-susemanager-client >= 1.0.4-0.5.1
  • susemanager >= 2.1.17-0.7.1
  • susemanager-client-config_en-pdf >= 2.1-0.15.6
  • susemanager-install_en-pdf >= 2.1-0.15.6
  • susemanager-jsp_en >= 2.1-0.15.5
  • susemanager-manuals_en >= 2.1-0.15.6
  • susemanager-proxy-quick_en-pdf >= 2.1-0.15.6
  • susemanager-reference_en-pdf >= 2.1-0.15.6
  • susemanager-schema >= 2.1.50.11-0.7.1
  • susemanager-sync-data >= 2.1.5-0.7.1
  • susemanager-tools >= 2.1.17-0.7.1
  • susemanager-user_en-pdf >= 2.1-0.15.6
  • tanukiwrapper >= 3.2.3-0.10.3
Builds
SAT Patch Nr: 10309
SUSE Manager 1.7 for SLE 11 SP2
  • sm-ncc-sync-data >= 1.7.21-0.5.1
  • smdba >= 1.5-0.6.2.1
  • spacecmd >= 1.7.7.12-0.5.1
  • spacewalk-backend >= 1.7.38.34-0.5.1
  • spacewalk-backend-app >= 1.7.38.34-0.5.1
  • spacewalk-backend-applet >= 1.7.38.34-0.5.1
  • spacewalk-backend-config-files >= 1.7.38.34-0.5.1
  • spacewalk-backend-config-files-common >= 1.7.38.34-0.5.1
  • spacewalk-backend-config-files-tool >= 1.7.38.34-0.5.1
  • spacewalk-backend-iss >= 1.7.38.34-0.5.1
  • spacewalk-backend-iss-export >= 1.7.38.34-0.5.1
  • spacewalk-backend-libs >= 1.7.38.34-0.5.1
  • spacewalk-backend-package-push-server >= 1.7.38.34-0.5.1
  • spacewalk-backend-server >= 1.7.38.34-0.5.1
  • spacewalk-backend-sql >= 1.7.38.34-0.5.1
  • spacewalk-backend-sql-oracle >= 1.7.38.34-0.5.1
  • spacewalk-backend-sql-postgresql >= 1.7.38.34-0.5.1
  • spacewalk-backend-tools >= 1.7.38.34-0.5.1
  • spacewalk-backend-xml-export-libs >= 1.7.38.34-0.5.1
  • spacewalk-backend-xmlrpc >= 1.7.38.34-0.5.1
  • spacewalk-backend-xp >= 1.7.38.34-0.5.1
  • spacewalk-branding >= 1.7.1.13-0.5.1
  • spacewalk-java >= 1.7.54.34-0.5.1
  • spacewalk-java-config >= 1.7.54.34-0.5.1
  • spacewalk-java-lib >= 1.7.54.34-0.5.1
  • spacewalk-java-oracle >= 1.7.54.34-0.5.1
  • spacewalk-java-postgresql >= 1.7.54.34-0.5.1
  • spacewalk-setup >= 1.7.9.12-0.5.1
  • spacewalk-taskomatic >= 1.7.54.34-0.5.1
  • susemanager >= 1.7.30-0.5.2
  • susemanager-schema >= 1.7.56.24-0.7.1
  • susemanager-tools >= 1.7.30-0.5.2
Builds
SAT Patch Nr: 10671


Status of this issue by product and package

Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification.

Product(s) Source package State
SUSE Manager Server 2.1 cobbler Released