← Vulnerability feed

Vulnerability record · CVE-2022-21952 · published 22 June 2022

CVE-2022-21952: Suse manager server missing authentication for critical function vulnerability

Suse · Manager Server

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.

7.5 CVSS 3.1 High EPSS 1.5% · top 26.0% CWE-306 · Missing authentication for critical functionCWE-770 · Allocation without limits
7.5CVSS 3.1 base score, v2 5.0
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
7 Jul 2026Last modified by NVD

Description

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.suse.com/show_bug.cgi?id=1199512 ExploitIssue TrackingThird Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1199512 ExploitIssue TrackingThird Party Advisory

Track CVE-2022-21952 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-31431Linux kernel algif_aead in-place crypto operation flawThe Linux kernel's algif_aead AF_ALG AEAD interface operated in-place on buffers that come from different mappings, a flaw the fix resolves by revert…KEVEPSS 3.4%analysed7.8CVE-2021-4034polkit pkexec argument handling flaw allows local root escalationpkexec, the setuid polkit utility for running commands as privileged users, mishandles the calling parameter count and ends up treating environment v…KEVEPSS 94%analysed7.5CVE-2023-29552Service Location Protocol unauthenticated service registration enables DoS amplificationThe Service Location Protocol (SLP, RFC 2608) permits an unauthenticated, remote attacker to register arbitrary services. This allows spoofed UDP tra…KEVEPSS 64%analysed9.4CVE-2023-22644Suse manager server vulnerabilityA user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perf…EPSS 0.46%7.8CVE-2022-27239Samba cifs-utils out-of-bounds write vulnerabilityIn cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining…EPSS 0.58%5.4CVE-2022-43754Suse manager server cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Mod…EPSS 0.41%5.3CVE-2022-31248Suse manager server vulnerabilityA Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to disc…EPSS 1.0%4.3CVE-2022-43753Suse manager server path traversal vulnerabilityA Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for…EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2022-21952), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.