<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for supportutils</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2023:3803-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2023-09-27T12:35:44Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2023-09-27T12:35:44Z</InitialReleaseDate>
    <CurrentReleaseDate>2023-09-27T12:35:44Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for supportutils</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for supportutils fixes the following issues:

Security Fixes:

- CVE-2022-45154: Removed iSCSI passwords (bsc#1207598).

Other fixes:

- Changes in version 3.1.26
  + powerpc plugin to collect the slots and active memory (bsc#1210950)
  + A Cleartext Storage of Sensitive Information vulnerability CVE-2022-45154
  + supportconfig: collect BPF information (pr#154)
  + Added additional iscsi information (pr#155)

- Added run time detection (bsc#1213127)

- Changes for supportutils version 3.1.25
  + Removed iSCSI passwords CVE-2022-45154 (bsc#1207598)
  + powerpc: Collect lsslot,amsstat, and opal elogs (pr#149)
  + powerpc: collect invscout logs (pr#150)
  + powerpc: collect RMC status logs (pr#151)
  + Added missing nvme nbft commands (bsc#1211599)
  + Fixed invalid nvme commands (bsc#1211598)
  + Added missing podman information (PED-1703, bsc#1181477)
  + Removed dependency on sysfstools
  + Check for systool use (bsc#1210015)
  + Added selinux checking (bsc#1209979)
  + Updated SLES_VER matrix

- Fixed missing status detail for apparmor (bsc#1196933)
- Corrected invalid argument list in docker.txt (bsc#1206608)
- Applies limit equally to sar data and text files (bsc#1207543)
- Collects hwinfo hardware logs (bsc#1208928)
- Collects lparnumascore logs (issue#148)

- Add dependency to `numactl` on ppc64le and `s390x`, this enforces
  that `numactl --hardware` data is provided in supportconfigs

- Changes to supportconfig.rc version 3.1.11-35
  + Corrected _sanitize_file to include iscsi.conf and others (bsc#1206402)

- Changes to supportconfig version 3.1.11-46.4
  + Added plymouth_info 

- Changes to getappcore version 1.53.02
  + The location of chkbin was updated earlier. This documents that
    change (bsc#1205533, bsc#1204942)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES15-SP1-SAP-Azure-LI-BYOS-Production-2023-3803,Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production-2023-3803,Image SLES15-SP2-BYOS-Azure-2023-3803,Image SLES15-SP2-HPC-BYOS-Azure-2023-3803,Image SLES15-SP2-SAP-Azure-2023-3803,Image SLES15-SP2-SAP-Azure-LI-BYOS-Production-2023-3803,Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production-2023-3803,Image SLES15-SP2-SAP-BYOS-Azure-2023-3803,Image SLES15-SP2-SAP-BYOS-EC2-HVM-2023-3803,Image SLES15-SP2-SAP-BYOS-GCE-2023-3803,Image SLES15-SP2-SAP-EC2-HVM-2023-3803,Image SLES15-SP2-SAP-GCE-2023-3803,SUSE-2023-3803,SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-3803,SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-3803,SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-3803,SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-3803,SUSE-SLE-Product-SLES_SAP-15-SP1-2023-3803,SUSE-SLE-Product-SLES_SAP-15-SP2-2023-3803,SUSE-Storage-7-2023-3803</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233803-1/</URL>
      <Description>Link for SUSE-SU-2023:3803-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2023-September/031719.html</URL>
      <Description>E-Mail link for SUSE-SU-2023:3803-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181477</URL>
      <Description>SUSE Bug 1181477</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196933</URL>
      <Description>SUSE Bug 1196933</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1204942</URL>
      <Description>SUSE Bug 1204942</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1205533</URL>
      <Description>SUSE Bug 1205533</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1206402</URL>
      <Description>SUSE Bug 1206402</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1206608</URL>
      <Description>SUSE Bug 1206608</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1207543</URL>
      <Description>SUSE Bug 1207543</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1207598</URL>
      <Description>SUSE Bug 1207598</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1208928</URL>
      <Description>SUSE Bug 1208928</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209979</URL>
      <Description>SUSE Bug 1209979</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1210015</URL>
      <Description>SUSE Bug 1210015</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1210950</URL>
      <Description>SUSE Bug 1210950</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1211598</URL>
      <Description>SUSE Bug 1211598</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1211599</URL>
      <Description>SUSE Bug 1211599</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1213127</URL>
      <Description>SUSE Bug 1213127</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-45154/</URL>
      <Description>SUSE CVE CVE-2022-45154 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Image SLES15-SP1-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP1-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP1-SAP-Azure-LI-BYOS-Production">Image SLES15-SP1-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production">Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP2-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP2-BYOS-Azure">Image SLES15-SP2-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-HPC-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP2-HPC-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP2-HPC-BYOS-Azure">Image SLES15-SP2-HPC-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-Azure">
        <FullProductName ProductID="Image SLES15-SP2-SAP-Azure">Image SLES15-SP2-SAP-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP2-SAP-Azure-LI-BYOS-Production">Image SLES15-SP2-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production">Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP2-SAP-BYOS-Azure">Image SLES15-SP2-SAP-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP2-SAP-BYOS-EC2-HVM">Image SLES15-SP2-SAP-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP2-SAP-BYOS-GCE">Image SLES15-SP2-SAP-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP2-SAP-EC2-HVM">Image SLES15-SP2-SAP-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-SAP-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP2-SAP-GCE">
        <FullProductName ProductID="Image SLES15-SP2-SAP-GCE">Image SLES15-SP2-SAP-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 7">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 7">
        <FullProductName ProductID="SUSE Enterprise Storage 7" CPE="cpe:/o:suse:ses:7">SUSE Enterprise Storage 7</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp1">SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp2">SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp1">SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp2">SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1" CPE="cpe:/o:suse:sles_sap:15:sp1">SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2" CPE="cpe:/o:suse:sles_sap:15:sp2">SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="supportutils-3.1.26-150000.5.50.1">
      <FullProductName ProductID="supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1</FullProductName>
    </Branch>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP1-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP1-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-BYOS-Azure:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-HPC-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-HPC-BYOS-Azure:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-HPC-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-Azure">
      <FullProductName ProductID="Image SLES15-SP2-SAP-Azure:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-SAP-BYOS-Azure:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-SAP-BYOS-EC2-HVM:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-SAP-BYOS-GCE:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-SAP-EC2-HVM:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-SAP-GCE">
      <FullProductName ProductID="Image SLES15-SP2-SAP-GCE:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of Image SLES15-SP2-SAP-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 7">
      <FullProductName ProductID="SUSE Enterprise Storage 7:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of SUSE Enterprise Storage 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP1-LTSS:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of SUSE Linux Enterprise Server 15 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP1:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="supportutils-3.1.26-150000.5.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:supportutils-3.1.26-150000.5.50.1">supportutils-3.1.26-150000.5.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise Server 12 supportutils version 3.0.10-95.51.1CWE-312: Cleartext Storage of Sensitive Information and prior versions. SUSE Linux Enterprise Server 15 supportutils version 3.1.21-150000.5.44.1 and prior versions. SUSE Linux Enterprise Server 15 SP3 supportutils version 3.1.21-150300.7.35.15.1 and prior versions.</Note>
    </Notes>
    <CVE>CVE-2022-45154</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-BYOS-Azure:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-HPC-BYOS-Azure:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-Azure:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-BYOS-Azure:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-BYOS-EC2-HVM:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-BYOS-GCE:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-EC2-HVM:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>Image SLES15-SP2-SAP-GCE:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>SUSE Enterprise Storage 7:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP1-LTSS:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP1:supportutils-3.1.26-150000.5.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:supportutils-3.1.26-150000.5.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233803-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-45154.html</URL>
        <Description>CVE-2022-45154</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1207598</URL>
        <Description>SUSE Bug 1207598</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
