SUSE-SU-2018:3811-1

    Dashboard / Vulnerabilities / SUSE-SU-2018:3811-1

    SUSE-SU-2018:3811-1

    Published: 19 Nov 2018Last Modified: 4 Feb 2026

    Summary: Security update for SUSE Manager Server 3.1

    Details: This update includes the following new features: - Add support for postgresql 10 (fate#325659) This update fixes the following issues: py26-compat-salt: - Update Salt version to 2016.11.10 - CVE-2018-15750: Fixed directory traversal vulnerability in salt-api (bsc#1113698). - CVE-2018-15751: Fixed remote authentication bypass in salt-api(netapi) that allows to execute arbitrary commands (bsc#1113699). - Fix wrong recurse behavior on for linux_acl.present (bsc#1106164) - Adding backport for string arg normalization and fix for SUSE ES os - Prepend current directory when path is just filename (bsc#1095942) smdba: - Add support for postgresql 10 (fate#325659) spacecmd: - Show group id on group_details (bsc#1111542) - State channels handling: Existing commands configchannel_create and configchannel_import were updated while system_scheduleapplyconfigchannels and configchannel_updateinitsls were added. spacewalk: - Add support for postgresql10 (fate#325659) spacewalk-backend: - Channels to be actually un-subscribed from the assigned systems when being removed using spacewalk-remove-channel tool(bsc#1104120) spacewalk-branding: - New messages are added for XMLRPC API for state channels spacewalk-doc-indexes: - Use nutch-core dependency instead of nutch spacewalk-java: - Change Requires to allow installing with both Tomcat 8 (SLE-12SP3) and 9 (SLE12-SP4) - Fix typo in messages (bsc#1111249) - Remove restrictions on SUSE Manager Channel subscriptions (bsc#1105724) - Added shortcut for editing Software Channel - Fix NullPointerException when refreshing deleted software channel (bsc#1094992) - Add last_boot to listSystems() API call - Check valid postgresql database version - Fix displayed number of systems requiring reboot in Tasks pane (bsc#1106875) - Changed localization strings for file summaries (bsc#1090676) - Added menu item entries for creating/deleting file preservation lists (bsc#1034030) - Better error handling when a websocket connection is aborted (bsc#1080474) - Remove the reference of channel from revision before deleting it(bsc#1107850) - Added link from virtualization tab to Scheduled > Pending Actions (bsc#1037389) - Speedup package listings(bsc#1100852) - Method to Unsubscribe channel from system(bsc#1104120) - Fix mgr-sync refresh when subscription was removed (bsc#1105720) - Fix an error in the system software channels UI due to SUSE product channels missing a corresponding synced channel (bsc#1105886) - XMLRPC API for state channels - Optimize execution of actions in minions (bsc#1099857) - Reschedule taskomatic jobs if task threads limit reached (bsc#1096511) - Logic constraint: results must be ordered and grouped by systemId first (bsc#1101033) - Do not wrap output if stderr is not present (bsc#1105074) spacewalk-search: - Discard commons-logging.properties removal on spec file, as OBS package does not contain it - Upgrade tika-core to 0.19.1 and adjust nutch-core (bsc#1109235) - Remove lib jar files and add them as build dependencies on spec - Limit number of old java logfiles (bsc#1107869) spacewalk-utils: - Fix typo at --phases option help spacewalk-web: - Fix typo in messages (bsc#1111249) - Fix Sles name in base channel filter (Visualization tab) (bsc#1042184) subscription-matcher: - Set core dumps location for IBM java (bsc#1107302) - Fix OutOfMemoryError crashes (bsc#1094524) - Updated to version 0.20 - Update partnumbers rule file (bsc#1095972) - Use intermediate object to store confirmed matches within a penalty group and prevent infinite reactivation of Inherited virtualization rule (bsc#1094524) susemanager: - Add new option --with-parent-channel to mgr-create-bootrap-repo to specify parent channel to use if multiple options are available (bsc#1104487) - Add support for postgresql10 (fate#325659) - Bootstrap repos for SLE12 SP4 (bsc#1107117) susemanager-branding-oss: - Use ASCII quotation marks in license file (bsc#1098970) susemanager-schema: - Check valid postgresql database version susemanager-sls: - Deploy SSL certificate during onboarding of openSUSE Leap 15.0 (bsc#1112163) - Removed the ssl certificate verification while checking bootstrap repo URL (bsc#1095220) - Removed the need for curl to be present at bootstrap phase (bsc#1095220) susemanager-sync-data: - SUSE OpenStack Cloud 9 enablement (bsc#1113557) - Add SUSE Manager 3.1 on SLES12 SP4 - Support SLE12 SP4 product family (bsc#1107117) - Add CaaSP 3.0 channels (bsc#1105045) Additionally some Java components have been split out of existing packages for better maintenance: - apache-mybatis - hadoop - icu4j - lucene - nekohtml - nutch-core - picocontainer - tagsoup - tika-core

    Affected packages

    Package

    Name: apache-mybatis

    Purl: pkg:rpm/suse/apache-mybatis&distro=SUSE%20Manager%20Server%203.1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.2.3-1.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High