Vulnerability Name:

CVE-2012-0426 (CCN-89644)

Assigned:2012-01-09
Published:2013-12-01
Updated:2013-12-03
Summary:Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
1.9 Low (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-362
Vulnerability Consequences:Unknown
References:Source: MITRE
Type: CNA
CVE-2012-0426

Source: CONFIRM
Type: UNKNOWN
http://download.novell.com/Download?buildid=DshQViDsMLE~

Source: CCN
Type: BID-64179
SUSE 'sap_suse_cluster_connector' Package CVE-2012-0426 Unspecified Local Security Vulnerability

Source: MISC
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=763793

Source: MISC
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=777453

Source: MISC
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=778273

Source: MISC
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=778293

Source: XF
Type: UNKNOWN
novell-cve20120426-unspec(89644)

Source: CCN
Type: Novell Web site
CVE-2012-0426

Source: CONFIRM
Type: Vendor Advisory
https://support.novell.com/security/cve/CVE-2012-0426.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:novell:suse_linux_enterprise_for_sap_applications:11:sp2:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:novell:suse_linux_enterprise_for_sap_applications:11:sp2:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20120426
    V
    CVE-2012-0426
    2022-05-20
    oval:org.opensuse.security:def:32246
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:32189
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:32096
    P
    Security update for dnsmasq (Important)
    2021-01-19
    oval:org.opensuse.security:def:28548
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:27941
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33376
    P
    Security update for sap_suse_cluster_connector
    2020-12-01
    oval:org.opensuse.security:def:28603
    P
    Security update for usbmuxd
    2020-12-01
    oval:org.opensuse.security:def:32489
    P
    apache2-mod_php5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28153
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31879
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29285
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:32594
    P
    perl-Tk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28294
    P
    Recommended update for ncurses (Important)
    2020-12-01
    oval:org.opensuse.security:def:31964
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27865
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:32655
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28499
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27877
    P
    Security update for Ruby
    2020-12-01
    oval:org.opensuse.security:def:33337
    P
    Security update for openssl1
    2020-12-01
    oval:org.opensuse.security:def:28587
    P
    Security update for libxslt
    2020-12-01
    oval:org.opensuse.security:def:32333
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28069
    P
    Security update for MozillaFirefox, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:31878
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28647
    P
    Security update for compat-wireless, compat-wireless-debuginfo, compat-wireless-debugsource, compat-wireless-kmp-default, compat-wireless-kmp-pae, compat-wireless-kmp-trace, compat-wireless-kmp-xen
    2020-12-01
    oval:org.opensuse.security:def:32545
    P
    libQtWebKit4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28210
    P
    Security update for libofx (Important)
    2020-12-01
    oval:org.opensuse.security:def:31890
    P
    Security update for exempi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29321
    P
    Security update for sap_suse_cluster_connector
    2020-12-01
    oval:org.opensuse.security:def:32633
    P
    apache2-mod_jk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28446
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:27866
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:32699
    P
    ldapsmb on GA media (Moderate)
    2020-12-01
    BACK
    novell suse linux enterprise for sap applications 11 sp2
    novell suse linux enterprise for sap applications 11 sp2