<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for SUSE Manager Server 3.2</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2019:1790-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-07-09T13:22:02Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-07-09T13:22:02Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-07-09T13:22:02Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for SUSE Manager Server 3.2</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update fixes the following issues:

release-notes-susemanager:

- Fix invalid characters in ncurses mode (bsc#1102770)

spacewalk-backend:

- Fix for CVE-2019-10136. An attacker with a valid, but expired,
  authenticated set of headers could move some digits around,
  artificially extending the session validity without modifying
  the checksum. (bsc#1136480)

spacewalk-web:

- Change WebUI string version to 3.2.9

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2019-1790,SUSE-SUSE-Manager-Proxy-3.2-2019-1790,SUSE-SUSE-Manager-Server-3.2-2019-1790</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20191790-1/</URL>
      <Description>Link for SUSE-SU-2019:1790-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2019-July/005676.html</URL>
      <Description>E-Mail link for SUSE-SU-2019:1790-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1102770</URL>
      <Description>SUSE Bug 1102770</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1136476</URL>
      <Description>SUSE Bug 1136476</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1136480</URL>
      <Description>SUSE Bug 1136480</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10136/</URL>
      <Description>SUSE CVE CVE-2019-10136 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10137/</URL>
      <Description>SUSE CVE CVE-2019-10137 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Manager Proxy 3.2">
      <Branch Type="Product Name" Name="SUSE Manager Proxy 3.2">
        <FullProductName ProductID="SUSE Manager Proxy 3.2" CPE="cpe:/o:suse:suse-manager-proxy:3.2">SUSE Manager Proxy 3.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 3.2">
      <Branch Type="Product Name" Name="SUSE Manager Server 3.2">
        <FullProductName ProductID="SUSE Manager Server 3.2" CPE="cpe:/o:suse:suse-manager-server:3.2">SUSE Manager Server 3.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="release-notes-susemanager-3.2.9-6.35.1">
      <FullProductName ProductID="release-notes-susemanager-3.2.9-6.35.1">release-notes-susemanager-3.2.9-6.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="release-notes-susemanager-proxy-3.2.9-0.16.27.1">
      <FullProductName ProductID="release-notes-susemanager-proxy-3.2.9-0.16.27.1">release-notes-susemanager-proxy-3.2.9-0.16.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-2.8.57.17-3.33.1">spacewalk-backend-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-app-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-app-2.8.57.17-3.33.1">spacewalk-backend-app-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-applet-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-applet-2.8.57.17-3.33.1">spacewalk-backend-applet-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-cdn-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-cdn-2.8.57.17-3.33.1">spacewalk-backend-cdn-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-config-files-2.8.57.17-3.33.1">spacewalk-backend-config-files-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-common-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-config-files-common-2.8.57.17-3.33.1">spacewalk-backend-config-files-common-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-tool-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-config-files-tool-2.8.57.17-3.33.1">spacewalk-backend-config-files-tool-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-iss-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-iss-2.8.57.17-3.33.1">spacewalk-backend-iss-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-iss-export-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-iss-export-2.8.57.17-3.33.1">spacewalk-backend-iss-export-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-libs-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-libs-2.8.57.17-3.33.1">spacewalk-backend-libs-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-package-push-server-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-package-push-server-2.8.57.17-3.33.1">spacewalk-backend-package-push-server-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-server-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-server-2.8.57.17-3.33.1">spacewalk-backend-server-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-sql-2.8.57.17-3.33.1">spacewalk-backend-sql-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql-oracle-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-sql-oracle-2.8.57.17-3.33.1">spacewalk-backend-sql-oracle-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1">spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-tools-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-tools-2.8.57.17-3.33.1">spacewalk-backend-tools-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1">spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-xmlrpc-2.8.57.17-3.33.1">
      <FullProductName ProductID="spacewalk-backend-xmlrpc-2.8.57.17-3.33.1">spacewalk-backend-xmlrpc-2.8.57.17-3.33.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-base-2.8.7.17-3.30.1">
      <FullProductName ProductID="spacewalk-base-2.8.7.17-3.30.1">spacewalk-base-2.8.7.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-base-minimal-2.8.7.17-3.30.1">
      <FullProductName ProductID="spacewalk-base-minimal-2.8.7.17-3.30.1">spacewalk-base-minimal-2.8.7.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-base-minimal-config-2.8.7.17-3.30.1">
      <FullProductName ProductID="spacewalk-base-minimal-config-2.8.7.17-3.30.1">spacewalk-base-minimal-config-2.8.7.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-dobby-2.8.7.17-3.30.1">
      <FullProductName ProductID="spacewalk-dobby-2.8.7.17-3.30.1">spacewalk-dobby-2.8.7.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-html-2.8.7.17-3.30.1">
      <FullProductName ProductID="spacewalk-html-2.8.7.17-3.30.1">spacewalk-html-2.8.7.17-3.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-proxy-broker-2.8.5.6-3.11.1">
      <FullProductName ProductID="spacewalk-proxy-broker-2.8.5.6-3.11.1">spacewalk-proxy-broker-2.8.5.6-3.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-proxy-common-2.8.5.6-3.11.1">
      <FullProductName ProductID="spacewalk-proxy-common-2.8.5.6-3.11.1">spacewalk-proxy-common-2.8.5.6-3.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-proxy-management-2.8.5.6-3.11.1">
      <FullProductName ProductID="spacewalk-proxy-management-2.8.5.6-3.11.1">spacewalk-proxy-management-2.8.5.6-3.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-proxy-package-manager-2.8.5.6-3.11.1">
      <FullProductName ProductID="spacewalk-proxy-package-manager-2.8.5.6-3.11.1">spacewalk-proxy-package-manager-2.8.5.6-3.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-proxy-redirect-2.8.5.6-3.11.1">
      <FullProductName ProductID="spacewalk-proxy-redirect-2.8.5.6-3.11.1">spacewalk-proxy-redirect-2.8.5.6-3.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-proxy-salt-2.8.5.6-3.11.1">
      <FullProductName ProductID="spacewalk-proxy-salt-2.8.5.6-3.11.1">spacewalk-proxy-salt-2.8.5.6-3.11.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susemanager-web-libs-2.8.7.17-3.30.1">
      <FullProductName ProductID="susemanager-web-libs-2.8.7.17-3.30.1">susemanager-web-libs-2.8.7.17-3.30.1</FullProductName>
    </Branch>
    <Relationship ProductReference="release-notes-susemanager-proxy-3.2.9-0.16.27.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:release-notes-susemanager-proxy-3.2.9-0.16.27.1">release-notes-susemanager-proxy-3.2.9-0.16.27.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-backend-2.8.57.17-3.33.1">spacewalk-backend-2.8.57.17-3.33.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-libs-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-backend-libs-2.8.57.17-3.33.1">spacewalk-backend-libs-2.8.57.17-3.33.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-base-minimal-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-base-minimal-2.8.7.17-3.30.1">spacewalk-base-minimal-2.8.7.17-3.30.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-base-minimal-config-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-base-minimal-config-2.8.7.17-3.30.1">spacewalk-base-minimal-config-2.8.7.17-3.30.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-proxy-broker-2.8.5.6-3.11.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-proxy-broker-2.8.5.6-3.11.1">spacewalk-proxy-broker-2.8.5.6-3.11.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-proxy-common-2.8.5.6-3.11.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-proxy-common-2.8.5.6-3.11.1">spacewalk-proxy-common-2.8.5.6-3.11.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-proxy-management-2.8.5.6-3.11.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-proxy-management-2.8.5.6-3.11.1">spacewalk-proxy-management-2.8.5.6-3.11.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-proxy-package-manager-2.8.5.6-3.11.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-proxy-package-manager-2.8.5.6-3.11.1">spacewalk-proxy-package-manager-2.8.5.6-3.11.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-proxy-redirect-2.8.5.6-3.11.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-proxy-redirect-2.8.5.6-3.11.1">spacewalk-proxy-redirect-2.8.5.6-3.11.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-proxy-salt-2.8.5.6-3.11.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:spacewalk-proxy-salt-2.8.5.6-3.11.1">spacewalk-proxy-salt-2.8.5.6-3.11.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susemanager-web-libs-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.2">
      <FullProductName ProductID="SUSE Manager Proxy 3.2:susemanager-web-libs-2.8.7.17-3.30.1">susemanager-web-libs-2.8.7.17-3.30.1 as a component of SUSE Manager Proxy 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="release-notes-susemanager-3.2.9-6.35.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:release-notes-susemanager-3.2.9-6.35.1">release-notes-susemanager-3.2.9-6.35.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-2.8.57.17-3.33.1">spacewalk-backend-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-app-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-app-2.8.57.17-3.33.1">spacewalk-backend-app-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-applet-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-applet-2.8.57.17-3.33.1">spacewalk-backend-applet-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-config-files-2.8.57.17-3.33.1">spacewalk-backend-config-files-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-common-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-config-files-common-2.8.57.17-3.33.1">spacewalk-backend-config-files-common-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-tool-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-config-files-tool-2.8.57.17-3.33.1">spacewalk-backend-config-files-tool-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-iss-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-iss-2.8.57.17-3.33.1">spacewalk-backend-iss-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-iss-export-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-iss-export-2.8.57.17-3.33.1">spacewalk-backend-iss-export-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-libs-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-libs-2.8.57.17-3.33.1">spacewalk-backend-libs-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-package-push-server-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-package-push-server-2.8.57.17-3.33.1">spacewalk-backend-package-push-server-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-server-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-server-2.8.57.17-3.33.1">spacewalk-backend-server-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-sql-2.8.57.17-3.33.1">spacewalk-backend-sql-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql-oracle-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-sql-oracle-2.8.57.17-3.33.1">spacewalk-backend-sql-oracle-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1">spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-tools-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-tools-2.8.57.17-3.33.1">spacewalk-backend-tools-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1">spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-xmlrpc-2.8.57.17-3.33.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-backend-xmlrpc-2.8.57.17-3.33.1">spacewalk-backend-xmlrpc-2.8.57.17-3.33.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-base-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-base-2.8.7.17-3.30.1">spacewalk-base-2.8.7.17-3.30.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-base-minimal-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-base-minimal-2.8.7.17-3.30.1">spacewalk-base-minimal-2.8.7.17-3.30.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-base-minimal-config-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-base-minimal-config-2.8.7.17-3.30.1">spacewalk-base-minimal-config-2.8.7.17-3.30.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-html-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:spacewalk-html-2.8.7.17-3.30.1">spacewalk-html-2.8.7.17-3.30.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susemanager-web-libs-2.8.7.17-3.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.2">
      <FullProductName ProductID="SUSE Manager Server 3.2:susemanager-web-libs-2.8.7.17-3.30.1">susemanager-web-libs-2.8.7.17-3.30.1 as a component of SUSE Manager Server 3.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.</Note>
    </Notes>
    <CVE>CVE-2019-10136</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager Proxy 3.2:release-notes-susemanager-proxy-3.2.9-0.16.27.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-backend-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-backend-libs-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-base-minimal-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-base-minimal-config-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-broker-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-common-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-management-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-package-manager-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-redirect-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-salt-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:susemanager-web-libs-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:release-notes-susemanager-3.2.9-6.35.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-app-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-applet-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-config-files-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-config-files-common-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-config-files-tool-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-iss-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-iss-export-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-libs-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-package-push-server-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-server-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-sql-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-sql-oracle-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-tools-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-xmlrpc-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-base-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-base-minimal-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-base-minimal-config-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-html-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:susemanager-web-libs-2.8.7.17-3.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20191790-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10136.html</URL>
        <Description>CVE-2019-10136</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1136480</URL>
        <Description>SUSE Bug 1136480</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or can execute arbitrary code in the context of the httpd process.</Note>
    </Notes>
    <CVE>CVE-2019-10137</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager Proxy 3.2:release-notes-susemanager-proxy-3.2.9-0.16.27.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-backend-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-backend-libs-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-base-minimal-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-base-minimal-config-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-broker-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-common-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-management-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-package-manager-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-redirect-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:spacewalk-proxy-salt-2.8.5.6-3.11.1</ProductID>
        <ProductID>SUSE Manager Proxy 3.2:susemanager-web-libs-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:release-notes-susemanager-3.2.9-6.35.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-app-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-applet-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-config-files-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-config-files-common-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-config-files-tool-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-iss-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-iss-export-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-libs-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-package-push-server-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-server-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-sql-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-sql-oracle-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-sql-postgresql-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-tools-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-xml-export-libs-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-backend-xmlrpc-2.8.57.17-3.33.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-base-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-base-minimal-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-base-minimal-config-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:spacewalk-html-2.8.7.17-3.30.1</ProductID>
        <ProductID>SUSE Manager Server 3.2:susemanager-web-libs-2.8.7.17-3.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2019/suse-su-20191790-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10137.html</URL>
        <Description>CVE-2019-10137</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1136476</URL>
        <Description>SUSE Bug 1136476</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
