rmt-server-pubcloud allows to escalate from user _rmt to root

CVE-2022-31254
7.8HIGH

Key Information

Vendor
Suse
Status
Suse Linux Enterprise Server For SAP 15
Suse Linux Enterprise Server For SAP 15-sp1
Suse Manager Server 4.1
Opensuse Leap 15.3
Vendor
CVE Published:
7 February 2023

Summary

A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10. SUSE Linux Enterprise Server for SAP 15-SP1 rmt-server versions prior to 2.10. SUSE Manager Server 4.1 rmt-server versions prior to 2.10. openSUSE Leap 15.3 rmt-server versions prior to 2.10. openSUSE Leap 15.4 rmt-server versions prior to 2.10.

Affected Version(s)

SUSE Linux Enterprise Server for SAP 15 < 2.10

SUSE Linux Enterprise Server for SAP 15-SP1 < 2.10

SUSE Manager Server 4.1 < 2.10

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Johannes Segitz of SUSE
.