CVE-2025-46809 (CNNVD-202507-3924)
中文标题:
SUSE Manager 日志信息泄露漏洞
英文标题:
Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logs
漏洞描述
中文描述:
SUSE Manager是德国SUSE公司的一套Linux服务器管理系统。该系统提供自动化软件管理、系统配置和监控等功能。 SUSE Manager存在日志信息泄露漏洞,该漏洞源于日志文件中暴露HTTP代理凭据。
英文描述:
A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1: from ? before 5.0.14-150600.4.17.1; Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.14-150600.4.17.1; Image SLES15-SP4-Manager-Proxy-4-3-BYOS: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: from ? before 4.3.33-150400.3.55.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE: from ? before 4.3.33-150400.3.55.2; SUSE Manager Proxy Module 4.3: from ? before 4.3.33-150400.3.55.2; SUSE Manager Server Module 4.3: from ? before 4.3.33-150400.3.55.2.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| SUSE | Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1 | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:container_suse_manager_4.3_proxy-httpd:4.3.16.9.67.1:*:*:*:*:*:*:*:*
|
| SUSE | Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1 | - | < 5.0.14-150600.4.17.1 | - |
cpe:2.3:a:suse:container_suse_manager_5.0_x86_64_proxy-httpd:5.0.5.7.23.1:*:*:*:*:*:*:*:*
|
| SUSE | Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 | - | < 5.0.14-150600.4.17.1 | - |
cpe:2.3:a:suse:container_suse_manager_5.0_x86_64_server:5.0.5.7.30.1:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-proxy-4-3-byos:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-proxy-4-3-byos-azure:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2 | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-proxy-4-3-byos-ec2:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-proxy-4-3-byos-gce:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-server-4-3-byos:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-server-4-3-byos-azure:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2 | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-server-4-3-byos-ec2:*:*:*:*:*:*:*:*
|
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:image_sles15-sp4-manager-server-4-3-byos-gce:*:*:*:*:*:*:*:*
|
| SUSE | SUSE Manager Proxy Module 4.3 | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:suse_manager_proxy_module_4.3:*:*:*:*:*:*:*:*
|
| SUSE | SUSE Manager Server Module 4.3 | - | < 4.3.33-150400.3.55.2 | - |
cpe:2.3:a:suse:suse_manager_server_module_4.3:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-46809 |
2025-11-11 15:23:22 | 2025-11-11 07:40:34 |
| NVD | nvd_CVE-2025-46809 |
2025-11-11 15:00:58 | 2025-11-11 07:48:22 |
| CNNVD | cnnvd_CNNVD-202507-3924 |
2025-11-11 15:12:52 | 2025-11-11 08:00:03 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 日志信息泄露
- cnnvd_id: 未提取 -> CNNVD-202507-3924
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']