Oval Definition:oval:org.opensuse.security:def:201910868
Revision Date:2021-10-24Version:1
Title:CVE-2019-10868
Description:

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the user to guess values.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-10868
Mitre CVE-2019-10868
SUSE CVE-2019-10868
Platform(s):openSUSE Leap 15.0
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub for SUSE Linux Enterprise 15
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • tryton-4.2.24-lp150.2.18 is installed
  • AND tryton is signed with openSUSE key
  • Definition Synopsis
  • SUSE Package Hub for SUSE Linux Enterprise 15 is installed
  • AND tryton-4.2.24-bp150.2.14.1 is installed
  • BACK