CVE-2022-31254
Summary
| CVE | CVE-2022-31254 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-07 10:15:00 UTC |
| Updated | 2023-02-14 23:21:00 UTC |
| Description | A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10. SUSE Linux Enterprise Server for SAP 15-SP1 rmt-server versions prior to 2.10. SUSE Manager Server 4.1 rmt-server versions prior to 2.10. openSUSE Leap 15.3 rmt-server versions prior to 2.10. openSUSE Leap 15.4 rmt-server versions prior to 2.10. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Opensuse | Leap | 15.3 | All | All | All |
| Operating System | Opensuse | Leap | 15.4 | All | All | All |
| Application | Opensuse | Rmt-server | All | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 15 | All | All | All |
| Operating System | Suse | Linux Enterprise Server | 15 | sp1 | All | All |
| Application | Suse | Manager Server | 4.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 1204285 – VUL-0: CVE-2022-31254: rmt-server: rmt-server-pubcloud allows to escalate from user _rmt to root | CONFIRM | bugzilla.suse.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Johannes Segitz of SUSE
Legacy QID Mappings
- 753494 SUSE Enterprise Linux Security Update for rmt-server (SUSE-SU-2023:0023-1)
- 753519 SUSE Enterprise Linux Security Update for rmt-server (SUSE-SU-2023:0022-1)
- 753523 SUSE Enterprise Linux Security Update for rmt-server (SUSE-SU-2023:0020-1)
- 753526 SUSE Enterprise Linux Security Update for rmt-server (SUSE-SU-2023:0019-1)
- 753530 SUSE Enterprise Linux Security Update for rmt-server (SUSE-SU-2023:0021-1)