SUSE Updates
2795Warning Date
Severity Level
Warning Number
Target Sector
10 January, 2021
● Critical
2021-2298
All
Description:
SUSE has released security updates to address multiple vulnerabilities in the following products:
- python-paramiko
- SUSE Linux Enterprise Module for Public Cloud 12
- tomcat
- SUSE Linux Enterprise Server for SAP 15
- SUSE Linux Enterprise Server 15-LTSS
- SUSE Linux Enterprise High Performance Computing 15-LTSS
- SUSE Linux Enterprise High Performance Computing 15-ESPOS
- SUSE Linux Enterprise Module for Web Scripting 15-SP2
- SUSE Linux Enterprise Module for Web Scripting 15-SP1
- python-defusedxml, python-freezegun, python-pkgconfig, python-python3-saml, python-xmlsec
- SUSE Enterprise Storage 6
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Information disclosure
- Remote code execution
Best practice and Recommendations:
The CERT team encourages users to review SUSE security advisory and apply the necessary updates:
- https://www.suse.com/support/update/announcement/2021/suse-su-20210038-1/
- https://www.suse.com/support/update/announcement/2021/suse-su-20210040-1/
- https://www.suse.com/support/update/announcement/2021/suse-su-20210041-1/
- https://www.suse.com/support/update/announcement/2021/suse-su-20210042-1/
- https://www.suse.com/support/update/announcement/2021/suse-su-20210048-1/