saphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.sls
Published Feb 15, 2023
7.8
HIGHCVSS 3.1
EPSS 0.22%
Description
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. SUSE Linux Enterprise Server for SAP 12-SP5 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. openSUSE Leap 15.4 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e.
Affected products
-
- Version saphanabootstrap-formulaStatusaffectedConstraints<0.13.1+git.1667812208.4db963e
- Version
-
- Version saphanabootstrap-formulaStatusaffectedConstraints<0.13.1+git.1667812208.4db963e
- Version
-
- Version saphanabootstrap-formulaStatusaffectedConstraints<0.13.1+git.1667812208.4db963e
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SUSE | SUSE Linux Enterprise Module for SAP Applications 15-SP1 | n/a |
| ||||||
| SUSE | SUSE Linux Enterprise Server for SAP 12-SP5 | n/a |
| ||||||
| openSUSE | openSUSE Leap 15.4 | n/a |
|
- 15
- 15.4
- 12
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://bugzilla.suse.com/show_bug.cgi?id=1205990 ExploitIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-48062 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1205990 | ExploitIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-48062 | Advisory |
Change history (0)
No recorded changes yet.