Manager Server

Vendor:

First CVE: Sep 22, 2014 · Active for 11 years

17
Total CVEs
More Total CVEs than 93% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
17.6%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Manager Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2014
11 years ago
Most Recent CVE
Apr 22, 2026
93 days ago

CVE Severity & Scoring

Manager Server17 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local8 (47.1%)
Network7 (41.2%)
Unknown2 (11.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High0 (0.0%)
Unknown2 (11.8%)
User Interaction
None14 (82.4%)
Unknown2 (11.8%)
Required1 (5.9%)
Privileges Required
Low10 (58.8%)
High0 (0.0%)
None5 (29.4%)
Unknown2 (11.8%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to
Apr 25, 20237.589YESNO
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to u
Jun 30, 20219.830NONO
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust availab
Jun 22, 20227.528NONO
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
Apr 27, 20227.826NONO
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager
Feb 7, 20237.825NONO
A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Fa
Jun 30, 20217.824NONO
A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch
Sep 17, 20209.323NONO
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2
Nov 10, 20225.421NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
3 CVEs
17.6% of CVEs· 98th percentile
Metasploit
2 CVEs
11.8% of CVEs· 97th percentile
Nuclei
1 CVE
5.9% of CVEs· 97th percentile
ExploitDB
1 CVE
5.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Manager Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.327.848.4%11
4.227.848.4%11
4.137.863.9%22
4.017.896.3%11