SUMA user enumeration via weak error message
A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46-1. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37-1.
- Published
- Jun 22, 2022
- Updated
- Jun 17, 2026
- EPSS
- 1.0% · 62th percentile
- CWE
- CWE-204
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
21
Monitor
Low priority for now.
- CVSS
- 21 / 40 · 5.3 / 10
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 0 / 30 · 1.0%
CNA vs NVD score
- NVD
- 5.3
- CNA · suse
- 5.3
- agree
The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.
Affected systems
| Vendor | Product | CPE |
|---|---|---|
| suse | manager server | cpe:2.3:a:suse:manager_server |
Affected versions
NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.
- suse manager server4.1 and later · before 4.1.46-1
- suse manager server4.2 and later · before 4.2.37-1
Versions reported by the vendor
Affected version ranges reported by the assigning authority (suse). Independent of NVD's CPE analysis and usually ahead of it.
SUSE SUSE Manager Server 4.1
- spacewalk-java and later · before 4.1.46-1affected
SUSE SUSE Manager Server 4.2
- spacewalk-java and later · before 4.2.37-1affected
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| SUSE:Manager Proxy 4.1 | release-notes-susemanager-proxy | before 4.1.15-150200.3.56.1 | 4.1.15-150200.3.56.1 |
| SUSE:Manager Proxy 4.2 | release-notes-susemanager-proxy | before 4.2.7-150300.3.31.2 | 4.2.7-150300.3.31.2 |
| SUSE:Manager Proxy 4.2 | release-notes-susemanager-proxy | before 4.2.8-150300.3.40.2 | 4.2.8-150300.3.40.2 |
| SUSE:Manager Proxy Module 4.2 | spacecmd | before 4.2.17-150300.4.21.4 | 4.2.17-150300.4.21.4 |
| SUSE:Manager Proxy Module 4.2 | spacewalk-backend | before 4.2.22-150300.4.23.1 | 4.2.22-150300.4.23.1 |
| SUSE:Manager Proxy Module 4.2 | spacewalk-certs-tools | before 4.2.16-150300.3.18.3 | 4.2.16-150300.3.18.3 |
| SUSE:Manager Proxy Module 4.2 | spacewalk-web | before 4.2.27-150300.3.21.7 | 4.2.27-150300.3.21.7 |
| SUSE:Manager Proxy Module 4.2 | supportutils-plugin-salt | before 1.2.0-150300.3.3.1 | 1.2.0-150300.3.3.1 |
| SUSE:Manager Server 4.1 | release-notes-susemanager | before 4.1.15-150200.3.80.1 | 4.1.15-150200.3.80.1 |
| SUSE:Manager Server 4.2 | release-notes-susemanager | before 4.2.8-150300.3.51.2 | 4.2.8-150300.3.51.2 |
| SUSE:Manager Server 4.2 | release-notes-susemanager | before 4.2.7-150300.3.44.1 | 4.2.7-150300.3.44.1 |
| SUSE:Manager Server Module 4.1 | golang-github-lusitaniae-apache_exporter | before 0.7.0-150200.2.6.2 | 0.7.0-150200.2.6.2 |
| SUSE:Manager Server Module 4.1 | golang-github-prometheus-node_exporter | before 1.3.0-150200.3.9.3 | 1.3.0-150200.3.9.3 |
| SUSE:Manager Server Module 4.1 | golang-github-QubitProducts-exporter_exporter | before 0.4.0-150200.6.12.2 | 0.4.0-150200.6.12.2 |
| SUSE:Manager Server Module 4.1 | patterns-suse-manager | before 4.1-150200.6.12.2 | 4.1-150200.6.12.2 |
| SUSE:Manager Server Module 4.1 | postgresql-jdbc | before 42.2.10-150200.3.8.2 | 42.2.10-150200.3.8.2 |
| SUSE:Manager Server Module 4.1 | prometheus-exporters-formula | before 0.9.5-150200.3.31.2 | 0.9.5-150200.3.31.2 |
| SUSE:Manager Server Module 4.1 | prometheus-formula | before 0.3.7-150200.3.21.2 | 0.3.7-150200.3.21.2 |
| SUSE:Manager Server Module 4.1 | py27-compat-salt | before 3000.3-150200.6.24.2 | 3000.3-150200.6.24.2 |
| SUSE:Manager Server Module 4.1 | spacecmd | before 4.1.18-150200.4.39.3 | 4.1.18-150200.4.39.3 |
| SUSE:Manager Server Module 4.1 | spacewalk-backend | before 4.1.31-150200.4.50.4 | 4.1.31-150200.4.50.4 |
| SUSE:Manager Server Module 4.1 | spacewalk-java | before 4.1.46-150200.3.71.5 | 4.1.46-150200.3.71.5 |
| SUSE:Manager Server Module 4.1 | spacewalk-setup | before 4.1.11-150200.3.18.2 | 4.1.11-150200.3.18.2 |
| SUSE:Manager Server Module 4.1 | spacewalk-utils | before 4.1.20-150200.3.30.2 | 4.1.20-150200.3.30.2 |
+88
Same product
suse: all recordsOther highest-scoring records for the same primary product.
- CVE-2023-22644JWT token compromise can allow malicious actions including Remote Code Execution (RCE)37Monitor
- CVE-2022-31254rmt-server-pubcloud allows to escalate from user _rmt to root31Monitor
- CVE-2022-21952SUMA unauthenticated remote DoS via resource exhaustion30Monitor
- CVE-2022-43754SUMA/UYUNI reflected cross site scripting in /rhn/audit/scap/Search.do21Monitor
- CVE-2022-43753SUMA/UYUNI arbitrary file disclosure vulnerability in ScapResultDownload17Monitor
- CVE-2022-31255SUMA/UYUNI directory path traversal vulnerability in CobblerSnipperViewAction17Monitor
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| suse:inter-server-sync | 0.2.2-150300.8.17.1 · SUSE:Manager Server Module 4.2 | Package registry (OSV) |
| suse:prometheus-formula | 0.6.2-150300.3.14.1 · SUSE:Manager Server Module 4.2 | Package registry (OSV) |
| suse:release-notes-susemanager | 4.1.15-150200.3.80.1 · SUSE:Manager Server 4.1 | Package registry (OSV) |
| suse:release-notes-susemanager-proxy | 4.1.15-150200.3.56.1 · SUSE:Manager Proxy 4.1 | Package registry (OSV) |
| suse:salt-netapi-client | 0.19.0-150300.3.6.1 · SUSE:Manager Server Module 4.2 | Package registry (OSV) |
| suse:smdba | 1.7.10-0.150300.3.6.1 · SUSE:Manager Server Module 4.2 | Package registry (OSV) |
| suse:spacecmd | 4.2.17-150300.4.21.4 · SUSE:Manager Proxy Module 4.2 | Package registry (OSV) |
| suse:spacewalk-backend | 4.2.22-150300.4.23.1 · SUSE:Manager Proxy Module 4.2 | Package registry (OSV) |
| suse:spacewalk-certs-tools | 4.2.16-150300.3.18.3 · SUSE:Manager Proxy Module 4.2 | Package registry (OSV) |
| suse:spacewalk-java | 4.2.38-150300.3.35.1 · SUSE:Manager Server Module 4.2 | Package registry (OSV) |
| suse:spacewalk-web | 4.2.27-150300.3.21.7 · SUSE:Manager Proxy Module 4.2 | Package registry (OSV) |
| suse:supportutils-plugin-salt | 1.2.0-150300.3.3.1 · SUSE:Manager Proxy Module 4.2 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
- Paolo PeregoSUSE
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
Attack conditions
- Anyone who can reach it over the internet can trigger it.
- No account or password is required.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- low · data can be read
- Integrity
- none
- Availability
- none
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- Low
- Integrity impact
- None
- Availability impact
- None
Weakness class (CWE)
CWE-204 · Observable Response DiscrepancyCVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd-primary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
Attack patterns (CAPEC)
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for all 385,000+ vulnerabilities; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpChange log
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →