CVE Database
/

CVE-2022-45154

Back to search

CVE-2022-45154

Published: Feb 15, 2023

Modified: Mar 18, 2025

PUBLISHED

CVSS v3.1

4.4

MEDIUM

Description

A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise Server 12 supportutils version 3.0.10-95.51.1CWE-312: Cleartext Storage of Sensitive Information and prior versions. SUSE Linux Enterprise Server 15 supportutils version 3.1.21-150000.5.44.1 and prior versions. SUSE Linux Enterprise Server 15 SP3 supportutils version 3.1.21-150300.7.35.15.1 and prior versions.

VendorProductVersions

SUSE

SUSE Linux Enterprise Server 12

affected
supportutils - <= 3.0.10-95.51.1CWE-312: Cleartext Storage of Sensitive Information

SUSE

SUSE Linux Enterprise Server 15

affected
supportutils - <= 3.1.21-150000.5.44.1

SUSE

SUSE Linux Enterprise Server 15 SP3

affected
supportutils - <= 3.1.21-150300.7.35.15.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now