SUSE-SU-2017:2453-1

    Dashboard / Vulnerabilities / SUSE-SU-2017:2453-1

    SUSE-SU-2017:2453-1

    Published: 13 Sept 2017Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary: Security update for SUSE Manager Server 3.0

    Details: This update for the SUSE Manager Server 3.0 provides several fixes and improvements. The following security issue has been fixed: spacewalk-java: - CVE-2017-7538: Do not allow HTML code injection via Cross Site Scripting (XSS) in the Organization Name. (bsc#1048968) Additionally, the following non-security issues have been fixed: salt-netapi-client: - Fix date format for Schedule. - Fix sending kwarg in payload in RunnerCall. - Better error handling in Runner and Wheel calls. - Increase the default SOCKET_TIMEOUT to 20 seconds smdba: - Do not set default_statistics_target. (bsc#1022286) - Support postgresql96. (bsc#1045152) - Prevent use of /var/lib/pgsql/data. (bsc#1024058) - Remove copyright message every time shown. - On systemd-enabled systems use it for start/stop PostgreSQL. (bsc#1024058) spacewalk-backend: - Increase rpclib timeout to 10 minutes. (bsc#1026930) - Adapt for the new gpgcheck flag for the channels. spacewalk-branding: - Fix overlapping text narrow window. (bsc#1009118) spacewalk-config: - Resolve comps.xml file for repositories. (bsc#1048528) spacewalk-java: - Delete and create new ServerNetAddress if it already exists on Hardware refresh. (bsc#1054225) - Fix enter key submit on ListTag filter input. (bsc#1048762) - Create VirtpollerData object with JSON content instead null. (bsc#1049170) - Prevent malformed XML if 'arch' is set to NULL. (bsc#1045575) - Resolve comps.xml file for repositories. (bsc#1048528) - Don't add default channel if AK is not valid. (bsc#1047656) - Add 'Enable GPG check' function for channels. - Regenerate pillar for the minions using the channel being modified. - Remove executable bit from service files. (bsc#1051518) - Fix wrong openscap xid. (bsc#1030898) - Fix overlapping text narrow window. (bsc#1009118) - Fix broken link. (bsc#1033999) - Fix alignment on the org details. (bsc#1017513) - Update channels.xml with OpenStack Cloud Continuous Delivery 6. (bsc#1039458) - Handle possible wrong UUIDs on SLE 11 minions. (bsc#1046218) - Allow blank key generation. (bsc#1032350) spacewalk-search: - Remove executable bit from service files. (bsc#1051518) spacewalk-setup-jabberd: - Change default backend for jabberd to sqlite. (bsc#1047155) spacewalk-web: - Fix enter key submit on ListTag filter input. (bsc#1048762) susemanager: - Do not use checkpoint_segments parameter during migrations. - Enable migration from postgresql94 to postgresql96. - Create bootstrap repository for SUSE Linux Enterprise Server for SAP 11 SP1. (bsc#1049471) - Adjust the bootstrap repository with SUSE Linux Enterprise 12 SP3 repositories. susemanager-docs_en: - Update text and image files. susemanager-schema: - Adapt for the new gpgcheck flag for the channels. susemanager-sync-data: - Add SUSE Manager Proxy 3.0 channels for SUSE Linux Enterprise Server 12 SP3. (bsc#1053850) - Support SUSE Enterprise Storage 5 and SUSE Linux Enterprise Server 12 SP3 for SAP Applications on ppc64le. (bsc#1028098) - Update channels.xml with OpenStack Cloud Continuous Delivery 6. (bsc#1039458) - Add SUSE Linux Enterprise 12 SP3 related products. (bsc#1037609) virtual-host-gatherer: - Implement kubernetes gatherer module. How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: spacewalk-service stop 3. Apply the patch using either zypper patch or YaST Online Update. 4. Upgrade the database schema: spacewalk-schema-upgrade 5. Start the Spacewalk service: spacewalk-service start

    Affected packages

    Package

    Name: salt-netapi-client

    Purl: pkg:rpm/suse/salt-netapi-client&distro=SUSE%20Manager%20Server%203.0

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.12.0-16.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High