Lucene search

K
cve[email protected]CVE-2022-45153
HistoryFeb 15, 2023 - 10:15 a.m.

CVE-2022-45153

2023-02-1510:15:16
CWE-276
web.nvd.nist.gov
33
cve
2022
45153
incorrect default permissions
suse
linux
enterprise
sap
applications
vulnerability
security
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects: SUSE Linux Enterprise Module for SAP Applications 15-SP1 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. SUSE Linux Enterprise Server for SAP 12-SP5 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e. openSUSE Leap 15.4 saphanabootstrap-formula versions prior to 0.13.1+git.1667812208.4db963e.

Affected configurations

NVD
Node
suselinux_enterprise_module_for_sap_applicationsMatch15sp1
OR
opensuseleapMatch15.4
OR
suselinux_enterprise_serverMatch12sp5sap

CNA Affected

[
  {
    "vendor": "SUSE",
    "product": "SUSE Linux Enterprise Module for SAP Applications 15-SP1",
    "versions": [
      {
        "version": "saphanabootstrap-formula",
        "status": "affected",
        "lessThan": "0.13.1+git.1667812208.4db963e",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "SUSE",
    "product": "SUSE Linux Enterprise Server for SAP 12-SP5",
    "versions": [
      {
        "version": "saphanabootstrap-formula",
        "status": "affected",
        "lessThan": "0.13.1+git.1667812208.4db963e",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "openSUSE",
    "product": "openSUSE Leap 15.4",
    "versions": [
      {
        "version": "saphanabootstrap-formula",
        "status": "affected",
        "lessThan": "0.13.1+git.1667812208.4db963e",
        "versionType": "custom"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2022-45153