<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for SUSE Manager Server 2.1</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2016:1367-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-05-19T20:37:06Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-05-19T20:37:06Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-05-19T20:37:06Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for SUSE Manager Server 2.1</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update for SUSE Manager Server 2.1 fixes the following issues:

cobbler:

- Add logrotate file for cobbler (bsc#976826)
- Fix cobbler yaboot handling (bsc#968406, bsc#966622)

osad:

- Fix file permissions (bsc#970550)

rhnlib:

- Use TLSv1_METHOD in SSL Context (bsc#970989)

spacewalk-backend:

- Mgr_ncc_sync: Adapt to bulk scheduling introduced in scheduleSingleSatRepoSync

spacewalk-branding:

- Fix link to 'Schedule patch updates' (bsc#973432)
- Fix link to scheduled action for SP migration (bsc#968257, bsc#974315)
- Fix: 'Advanced Search' title consistency

spacewalk-certs-tools:

- Fix file permissions (bsc#970550)

spacewalk-java:

- Recreate upgrade paths on every refresh (bsc#978166)
- Call cobbler sync after cobbler command is finished (bsc#966890)
- Under high load, the service wrapper may incorrectly interpret the inability
  to get a response in time from taskomatic and kill it (bsc#962253)
- Log permissions problems on channel access while SP migration (bsc#970223)
- Unittests: support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194)
- Mgr-sync: use bulk channel reposync (bsc#961002)
- Double the backslashes when reading the config files from java (bsc#958923)
- When generating repo metadata for a cloned channel, recursively fetch
  keywords from the original channel (bsc#970901)
- Better logging for SP Migration feature (bsc#970223)
- Fix: 'Advanced Search' title consistency
- CVE-2015-0284: XSS when altering user details and going somewhere where you are
  choosing user (bsc#922740)
- CVE-2016-3079, CVE-2016-2103, CVE-2016-2104, CVE-2016-3097: Fix multiple XSS
  vulnerabilities (bsc#973162, bsc#974011, bsc#974010, bsc#973550)
- BugFix: 'Systems &gt; Advanced Search' title and description consistency
  (bsc#966737)
- Fix: correct behavior with visibility conditions of sub-tabs in Systems/Misc
  page
- BugFix: add missing url mapping (bsc#961565)
- Fix kernel and initrd pathes for creating autoinstallation tries (bsc#966622)
- Fix tests for HAE-GEO on SLES 4 SAP (bsc#970425)
- Add unit tests for SLE-Live-Patching12 (bsc#924298)

spacewalk-utils:

- Bugfix: don't repeat channel labels
- Taskotop: a utility to monitor what Taskomatic is doing
- Fix file permissions (bsc#970550)

suseRegisterInfo:

- Fix file permissions (bsc#970550)

susemanager:

- Add packages to bootstrap repo (bsc#971237)
- Mgr-sync: use bulk channel reposync (bsc#961002)
- Mgr_ncc_sync: adapt to bulk scheduling introduced in
  scheduleSingleSatRepoSync
- Add SLES 4 SAP to mgr-create-bootstap-repo as an option (bsc#972341)
- Put packages only available in SLE12 SP1 in a seperate list (bsc#970672)
- Fix file permissions (bsc#970550)

susemanager-sync-data:

- Support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194)
- HAE-GEO is an addon product for SLES 4 SAP (bsc#970425)
- Add support for SLE-Live-Patching12 (bsc#924298, bsc#968851)

susemanager-tftpsync:

- Rename change_tftpd_proxies.py to sync_post_tftpd_proxies.py and change
  trigger type (bsc#966890)

How to apply this update:
1. Log in as root user to the SUSE Manager server.
2. Stop the Spacewalk service:
spacewalk-service stop
3. Apply the patch using either zypper patch or YaST Online Update.
4. Start the Spacewalk service:
spacewalk-service start
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">sleman21-suse-manager-21-201605-12567</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/</URL>
      <Description>Link for SUSE-SU-2016:1367-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2016-May/002076.html</URL>
      <Description>E-Mail link for SUSE-SU-2016:1367-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/922740</URL>
      <Description>SUSE Bug 922740</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/924298</URL>
      <Description>SUSE Bug 924298</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/958923</URL>
      <Description>SUSE Bug 958923</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/961002</URL>
      <Description>SUSE Bug 961002</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/961565</URL>
      <Description>SUSE Bug 961565</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/962253</URL>
      <Description>SUSE Bug 962253</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/966622</URL>
      <Description>SUSE Bug 966622</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/966737</URL>
      <Description>SUSE Bug 966737</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/966890</URL>
      <Description>SUSE Bug 966890</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/968257</URL>
      <Description>SUSE Bug 968257</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/968406</URL>
      <Description>SUSE Bug 968406</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/968851</URL>
      <Description>SUSE Bug 968851</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/970223</URL>
      <Description>SUSE Bug 970223</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/970425</URL>
      <Description>SUSE Bug 970425</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/970550</URL>
      <Description>SUSE Bug 970550</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/970672</URL>
      <Description>SUSE Bug 970672</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/970901</URL>
      <Description>SUSE Bug 970901</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/970989</URL>
      <Description>SUSE Bug 970989</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/971237</URL>
      <Description>SUSE Bug 971237</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/972341</URL>
      <Description>SUSE Bug 972341</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/973162</URL>
      <Description>SUSE Bug 973162</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/973432</URL>
      <Description>SUSE Bug 973432</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/973550</URL>
      <Description>SUSE Bug 973550</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/974010</URL>
      <Description>SUSE Bug 974010</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/974011</URL>
      <Description>SUSE Bug 974011</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/974315</URL>
      <Description>SUSE Bug 974315</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/976194</URL>
      <Description>SUSE Bug 976194</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/976826</URL>
      <Description>SUSE Bug 976826</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/978166</URL>
      <Description>SUSE Bug 978166</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0284/</URL>
      <Description>SUSE CVE CVE-2015-0284 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2103/</URL>
      <Description>SUSE CVE CVE-2016-2103 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2104/</URL>
      <Description>SUSE CVE CVE-2016-2104 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3079/</URL>
      <Description>SUSE CVE CVE-2016-3079 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-3097/</URL>
      <Description>SUSE CVE CVE-2016-3097 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Manager 2.1">
      <Branch Type="Product Name" Name="SUSE Manager 2.1">
        <FullProductName ProductID="SUSE Manager 2.1" CPE="cpe:/o:suse:suse-manager-server:2.1">SUSE Manager 2.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="cobbler-2.2.2-0.61.2">
      <FullProductName ProductID="cobbler-2.2.2-0.61.2">cobbler-2.2.2-0.61.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="osa-dispatcher-5.11.33.11-15.2">
      <FullProductName ProductID="osa-dispatcher-5.11.33.11-15.2">osa-dispatcher-5.11.33.11-15.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rhnlib-2.5.69.8-11.2">
      <FullProductName ProductID="rhnlib-2.5.69.8-11.2">rhnlib-2.5.69.8-11.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-2.1.55.25-24.5">spacewalk-backend-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-app-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-app-2.1.55.25-24.5">spacewalk-backend-app-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-applet-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-applet-2.1.55.25-24.5">spacewalk-backend-applet-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-config-files-2.1.55.25-24.5">spacewalk-backend-config-files-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-common-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-config-files-common-2.1.55.25-24.5">spacewalk-backend-config-files-common-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-tool-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-config-files-tool-2.1.55.25-24.5">spacewalk-backend-config-files-tool-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-iss-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-iss-2.1.55.25-24.5">spacewalk-backend-iss-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-iss-export-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-iss-export-2.1.55.25-24.5">spacewalk-backend-iss-export-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-libs-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-libs-2.1.55.25-24.5">spacewalk-backend-libs-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-package-push-server-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-package-push-server-2.1.55.25-24.5">spacewalk-backend-package-push-server-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-server-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-server-2.1.55.25-24.5">spacewalk-backend-server-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-sql-2.1.55.25-24.5">spacewalk-backend-sql-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql-oracle-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-sql-oracle-2.1.55.25-24.5">spacewalk-backend-sql-oracle-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql-postgresql-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-sql-postgresql-2.1.55.25-24.5">spacewalk-backend-sql-postgresql-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-tools-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-tools-2.1.55.25-24.5">spacewalk-backend-tools-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-xml-export-libs-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-xml-export-libs-2.1.55.25-24.5">spacewalk-backend-xml-export-libs-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-xmlrpc-2.1.55.25-24.5">
      <FullProductName ProductID="spacewalk-backend-xmlrpc-2.1.55.25-24.5">spacewalk-backend-xmlrpc-2.1.55.25-24.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-branding-2.1.33.16-18.2">
      <FullProductName ProductID="spacewalk-branding-2.1.33.16-18.2">spacewalk-branding-2.1.33.16-18.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-certs-tools-2.1.6.10-18.3">
      <FullProductName ProductID="spacewalk-certs-tools-2.1.6.10-18.3">spacewalk-certs-tools-2.1.6.10-18.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-2.1.165.23-20.1">
      <FullProductName ProductID="spacewalk-java-2.1.165.23-20.1">spacewalk-java-2.1.165.23-20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-config-2.1.165.23-20.1">
      <FullProductName ProductID="spacewalk-java-config-2.1.165.23-20.1">spacewalk-java-config-2.1.165.23-20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-lib-2.1.165.23-20.1">
      <FullProductName ProductID="spacewalk-java-lib-2.1.165.23-20.1">spacewalk-java-lib-2.1.165.23-20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-oracle-2.1.165.23-20.1">
      <FullProductName ProductID="spacewalk-java-oracle-2.1.165.23-20.1">spacewalk-java-oracle-2.1.165.23-20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-postgresql-2.1.165.23-20.1">
      <FullProductName ProductID="spacewalk-java-postgresql-2.1.165.23-20.1">spacewalk-java-postgresql-2.1.165.23-20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-taskomatic-2.1.165.23-20.1">
      <FullProductName ProductID="spacewalk-taskomatic-2.1.165.23-20.1">spacewalk-taskomatic-2.1.165.23-20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-utils-2.1.27.15-12.7">
      <FullProductName ProductID="spacewalk-utils-2.1.27.15-12.7">spacewalk-utils-2.1.27.15-12.7</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="suseRegisterInfo-2.1.12-14.2">
      <FullProductName ProductID="suseRegisterInfo-2.1.12-14.2">suseRegisterInfo-2.1.12-14.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susemanager-2.1.24-23.1">
      <FullProductName ProductID="susemanager-2.1.24-23.1">susemanager-2.1.24-23.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susemanager-sync-data-2.1.15-30.2">
      <FullProductName ProductID="susemanager-sync-data-2.1.15-30.2">susemanager-sync-data-2.1.15-30.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susemanager-tftpsync-2.1.2-11.2">
      <FullProductName ProductID="susemanager-tftpsync-2.1.2-11.2">susemanager-tftpsync-2.1.2-11.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susemanager-tools-2.1.24-23.1">
      <FullProductName ProductID="susemanager-tools-2.1.24-23.1">susemanager-tools-2.1.24-23.1</FullProductName>
    </Branch>
    <Relationship ProductReference="cobbler-2.2.2-0.61.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:cobbler-2.2.2-0.61.2">cobbler-2.2.2-0.61.2 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="osa-dispatcher-5.11.33.11-15.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2">osa-dispatcher-5.11.33.11-15.2 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="rhnlib-2.5.69.8-11.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:rhnlib-2.5.69.8-11.2">rhnlib-2.5.69.8-11.2 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5">spacewalk-backend-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-app-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5">spacewalk-backend-app-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-applet-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5">spacewalk-backend-applet-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5">spacewalk-backend-config-files-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-common-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5">spacewalk-backend-config-files-common-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-tool-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5">spacewalk-backend-config-files-tool-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-iss-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5">spacewalk-backend-iss-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-iss-export-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5">spacewalk-backend-iss-export-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-libs-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5">spacewalk-backend-libs-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-package-push-server-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5">spacewalk-backend-package-push-server-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-server-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5">spacewalk-backend-server-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5">spacewalk-backend-sql-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql-oracle-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5">spacewalk-backend-sql-oracle-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql-postgresql-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5">spacewalk-backend-sql-postgresql-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-tools-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5">spacewalk-backend-tools-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-xml-export-libs-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5">spacewalk-backend-xml-export-libs-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-xmlrpc-2.1.55.25-24.5" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5">spacewalk-backend-xmlrpc-2.1.55.25-24.5 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-branding-2.1.33.16-18.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2">spacewalk-branding-2.1.33.16-18.2 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-certs-tools-2.1.6.10-18.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3">spacewalk-certs-tools-2.1.6.10-18.3 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-2.1.165.23-20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1">spacewalk-java-2.1.165.23-20.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-config-2.1.165.23-20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1">spacewalk-java-config-2.1.165.23-20.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-lib-2.1.165.23-20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1">spacewalk-java-lib-2.1.165.23-20.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-oracle-2.1.165.23-20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1">spacewalk-java-oracle-2.1.165.23-20.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-postgresql-2.1.165.23-20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1">spacewalk-java-postgresql-2.1.165.23-20.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-taskomatic-2.1.165.23-20.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1">spacewalk-taskomatic-2.1.165.23-20.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-utils-2.1.27.15-12.7" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7">spacewalk-utils-2.1.27.15-12.7 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="suseRegisterInfo-2.1.12-14.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2">suseRegisterInfo-2.1.12-14.2 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="susemanager-2.1.24-23.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:susemanager-2.1.24-23.1">susemanager-2.1.24-23.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="susemanager-sync-data-2.1.15-30.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2">susemanager-sync-data-2.1.15-30.2 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="susemanager-tftpsync-2.1.2-11.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2">susemanager-tftpsync-2.1.2-11.2 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="susemanager-tools-2.1.24-23.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager 2.1">
      <FullProductName ProductID="SUSE Manager 2.1:susemanager-tools-2.1.24-23.1">susemanager-tools-2.1.24-23.1 as a component of SUSE Manager 2.1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.</Note>
    </Notes>
    <CVE>CVE-2015-0284</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager 2.1:cobbler-2.2.2-0.61.2</ProductID>
        <ProductID>SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2</ProductID>
        <ProductID>SUSE Manager 2.1:rhnlib-2.5.69.8-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7</ProductID>
        <ProductID>SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-2.1.24-23.1</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tools-2.1.24-23.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0284.html</URL>
        <Description>CVE-2015-0284</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/902915</URL>
        <Description>SUSE Bug 902915</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/922740</URL>
        <Description>SUSE Bug 922740</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969911</URL>
        <Description>SUSE Bug 969911</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.</Note>
    </Notes>
    <CVE>CVE-2016-2103</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager 2.1:cobbler-2.2.2-0.61.2</ProductID>
        <ProductID>SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2</ProductID>
        <ProductID>SUSE Manager 2.1:rhnlib-2.5.69.8-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7</ProductID>
        <ProductID>SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-2.1.24-23.1</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tools-2.1.24-23.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2103.html</URL>
        <Description>CVE-2016-2103</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/974011</URL>
        <Description>SUSE Bug 974011</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the package_name, (3) search_subscribed_channels, or (4) channel_filter parameter to software/packages/NameOverview.do; or unspecified vectors related to (5) &lt;input:hidden&gt; or (6) &lt;bean:message&gt; tags.</Note>
    </Notes>
    <CVE>CVE-2016-2104</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager 2.1:cobbler-2.2.2-0.61.2</ProductID>
        <ProductID>SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2</ProductID>
        <ProductID>SUSE Manager 2.1:rhnlib-2.5.69.8-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7</ProductID>
        <ProductID>SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-2.1.24-23.1</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tools-2.1.24-23.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2104.html</URL>
        <Description>CVE-2016-2104</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/974010</URL>
        <Description>SUSE Bug 974010</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).</Note>
    </Notes>
    <CVE>CVE-2016-3079</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager 2.1:cobbler-2.2.2-0.61.2</ProductID>
        <ProductID>SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2</ProductID>
        <ProductID>SUSE Manager 2.1:rhnlib-2.5.69.8-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7</ProductID>
        <ProductID>SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-2.1.24-23.1</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tools-2.1.24-23.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3079.html</URL>
        <Description>CVE-2016-3079</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/973162</URL>
        <Description>SUSE Bug 973162</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.</Note>
    </Notes>
    <CVE>CVE-2016-3097</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Manager 2.1:cobbler-2.2.2-0.61.2</ProductID>
        <ProductID>SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2</ProductID>
        <ProductID>SUSE Manager 2.1:rhnlib-2.5.69.8-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1</ProductID>
        <ProductID>SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7</ProductID>
        <ProductID>SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-2.1.24-23.1</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2</ProductID>
        <ProductID>SUSE Manager 2.1:susemanager-tools-2.1.24-23.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-3097.html</URL>
        <Description>CVE-2016-3097</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/973550</URL>
        <Description>SUSE Bug 973550</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
