SUSE-SU-2018:3811-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3811-1
SUSE-SU-2018:3811-1
Summary: Security update for SUSE Manager Server 3.1
Details: This update includes the following new features: - Add support for postgresql 10 (fate#325659) This update fixes the following issues: py26-compat-salt: - Update Salt version to 2016.11.10 - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api (bsc#1113698). - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi) that allows to execute arbitrary commands (bsc#1113699). - Fix wrong recurse behavior on for linux_acl.present (bsc#1106164) - Adding backport for string arg normalization and fix for SUSE ES os - Prepend current directory when path is just filename (bsc#1095942) smdba: - Add support for postgresql 10 (fate#325659) spacecmd: - Show group id on group_details (bsc#1111542) - State channels handling: Existing commands configchannel_create and configchannel_import were updated while system_scheduleapplyconfigchannels and configchannel_updateinitsls were added. spacewalk: - Add support for postgresql10 (fate#325659) spacewalk-backend: - Channels to be actually un-subscribed from the assigned systems when being removed using spacewalk-remove-channel tool(bsc#1104120) spacewalk-branding: - New messages are added for XMLRPC API for state channels spacewalk-doc-indexes: - Use nutch-core dependency instead of nutch spacewalk-java: - Change Requires to allow installing with both Tomcat 8 (SLE-12SP3) and 9 (SLE12-SP4) - Fix typo in messages (bsc#1111249) - Remove restrictions on SUSE Manager Channel subscriptions (bsc#1105724) - Added shortcut for editing Software Channel - Fix NullPointerException when refreshing deleted software channel (bsc#1094992) - Add last_boot to listSystems() API call - Check valid postgresql database version - Fix displayed number of systems requiring reboot in Tasks pane (bsc#1106875) - Changed localization strings for file summaries (bsc#1090676) - Added menu item entries for creating/deleting file preservation lists (bsc#1034030) - Better error handling when a websocket connection is aborted (bsc#1080474) - Remove the reference of channel from revision before deleting it(bsc#1107850) - Added link from virtualization tab to Scheduled > Pending Actions (bsc#1037389) - Speedup package listings(bsc#1100852) - Method to Unsubscribe channel from system(bsc#1104120) - Fix mgr-sync refresh when subscription was removed (bsc#1105720) - Fix an error in the system software channels UI due to SUSE product channels missing a corresponding synced channel (bsc#1105886) - XMLRPC API for state channels - Optimize execution of actions in minions (bsc#1099857) - Reschedule taskomatic jobs if task threads limit reached (bsc#1096511) - Logic constraint: results must be ordered and grouped by systemId first (bsc#1101033) - Do not wrap output if stderr is not present (bsc#1105074) spacewalk-search: - Discard commons-logging.properties removal on spec file, as OBS package does not contain it - Upgrade tika-core to 0.19.1 and adjust nutch-core (bsc#1109235) - Remove lib jar files and add them as build dependencies on spec - Limit number of old java logfiles (bsc#1107869) spacewalk-utils: - Fix typo at --phases option help spacewalk-web: - Fix typo in messages (bsc#1111249) - Fix Sles name in base channel filter (Visualization tab) (bsc#1042184) subscription-matcher: - Set core dumps location for IBM java (bsc#1107302) - Fix OutOfMemoryError crashes (bsc#1094524) - Updated to version 0.20 - Update partnumbers rule file (bsc#1095972) - Use intermediate object to store confirmed matches within a penalty group and prevent infinite reactivation of Inherited virtualization rule (bsc#1094524) susemanager: - Add new option --with-parent-channel to mgr-create-bootrap-repo to specify parent channel to use if multiple options are available (bsc#1104487) - Add support for postgresql10 (fate#325659) - Bootstrap repos for SLE12 SP4 (bsc#1107117) susemanager-branding-oss: - Use ASCII quotation marks in license file (bsc#1098970) susemanager-schema: - Check valid postgresql database version susemanager-sls: - Deploy SSL certificate during onboarding of openSUSE Leap 15.0 (bsc#1112163) - Removed the ssl certificate verification while checking bootstrap repo URL (bsc#1095220) - Removed the need for curl to be present at bootstrap phase (bsc#1095220) susemanager-sync-data: - SUSE OpenStack Cloud 9 enablement (bsc#1113557) - Add SUSE Manager 3.1 on SLES12 SP4 - Support SLE12 SP4 product family (bsc#1107117) - Add CaaSP 3.0 channels (bsc#1105045) Additionally some Java components have been split out of existing packages for better maintenance: - apache-mybatis - hadoop - icu4j - lucene - nekohtml - nutch-core - picocontainer - tagsoup - tika-core
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183811-1/, https://bugzilla.suse.com/1034030, https://bugzilla.suse.com/1037389, https://bugzilla.suse.com/1042184, https://bugzilla.suse.com/1080474, https://bugzilla.suse.com/1090676, https://bugzilla.suse.com/1094524, https://bugzilla.suse.com/1094992, https://bugzilla.suse.com/1095220, https://bugzilla.suse.com/1095942, https://bugzilla.suse.com/1095972, https://bugzilla.suse.com/1096511, https://bugzilla.suse.com/1098970, https://bugzilla.suse.com/1099857, https://bugzilla.suse.com/1100852, https://bugzilla.suse.com/1101033, https://bugzilla.suse.com/1104120, https://bugzilla.suse.com/1104487, https://bugzilla.suse.com/1105045, https://bugzilla.suse.com/1105074, https://bugzilla.suse.com/1105720, https://bugzilla.suse.com/1105724, https://bugzilla.suse.com/1105886, https://bugzilla.suse.com/1106164, https://bugzilla.suse.com/1106875, https://bugzilla.suse.com/1107117, https://bugzilla.suse.com/1107302, https://bugzilla.suse.com/1107850, https://bugzilla.suse.com/1107869, https://bugzilla.suse.com/1109235, https://bugzilla.suse.com/1111249, https://bugzilla.suse.com/1111542, https://bugzilla.suse.com/1112163, https://bugzilla.suse.com/1113557, https://bugzilla.suse.com/1113698, https://bugzilla.suse.com/1113699, https://www.suse.com/security/cve/CVE-2017-14695, https://www.suse.com/security/cve/CVE-2017-14696
Affected packages
Package
Name: apache-mybatis
Purl: pkg:rpm/suse/apache-mybatis&distro=SUSE%20Manager%20Server%203.1
Affected ranges
Type: ECOSYSTEM
Events:
