<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for for SUSE Manager 4.1</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2020:2647-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2020-09-16T12:22:50Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2020-09-16T12:22:50Z</InitialReleaseDate>
    <CurrentReleaseDate>2020-09-16T12:22:50Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for for SUSE Manager 4.1</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for SUSE Manager 4.1 fixes the following issues:

google-gson:

- Use packages from SUSE:SLE-15-SP2:Update:Products:Manager41:Update to fix building other packages.

httpcomponents-client:

- Use packages from SUSE:SLE-15-SP2:Update:Products:Manager41:Update to fix building other packages.

httpcomponents-core:

- Use packages from SUSE:SLE-15-SP2:Update:Products:Manager41:Update to fix building other packages.

salt-netapi-client:

- Refresh authentication module list to newer Salt versions

spacewalk-admin:

- Use the Salt API in authenticated and encrypted form (bsc#1175884, CVE-2020-8028)

spacewalk-java:

- Use the Salt API in authenticated and encrypted form (bsc#1175884, CVE-2020-8028)

spacewalk-setup:

- Use the Salt API in authenticated and encrypted form (bsc#1175884, CVE-2020-8028)

velocity:

- Use packages from SUSE:SLE-15-SP2:Update:Products:Manager41:Update to fix building other packages.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure-2020-2647,Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM-2020-2647,Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE-2020-2647,SUSE-2020-2647,SUSE-SLE-Module-SUSE-Manager-Server-4.1-2020-2647</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20202647-1/</URL>
      <Description>Link for SUSE-SU-2020:2647-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2020-September/007434.html</URL>
      <Description>E-Mail link for SUSE-SU-2020:2647-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1175884</URL>
      <Description>SUSE Bug 1175884</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8028/</URL>
      <Description>SUSE CVE CVE-2020-8028 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <Branch Type="Product Name" Name="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
        <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <Branch Type="Product Name" Name="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
        <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <Branch Type="Product Name" Name="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
        <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server Module 4.1">
      <Branch Type="Product Name" Name="SUSE Manager Server Module 4.1">
        <FullProductName ProductID="SUSE Manager Server Module 4.1" CPE="cpe:/o:suse:sle-module-suse-manager-server:4.1">SUSE Manager Server Module 4.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="google-gson-2.8.5-3.4.3">
      <FullProductName ProductID="google-gson-2.8.5-3.4.3">google-gson-2.8.5-3.4.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="httpcomponents-client-4.5.6-3.4.2">
      <FullProductName ProductID="httpcomponents-client-4.5.6-3.4.2">httpcomponents-client-4.5.6-3.4.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="httpcomponents-core-4.4.10-3.4.2">
      <FullProductName ProductID="httpcomponents-core-4.4.10-3.4.2">httpcomponents-core-4.4.10-3.4.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="salt-netapi-client-0.17.0-3.3.2">
      <FullProductName ProductID="salt-netapi-client-0.17.0-3.3.2">salt-netapi-client-0.17.0-3.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-admin-4.1.6-3.3.3">
      <FullProductName ProductID="spacewalk-admin-4.1.6-3.3.3">spacewalk-admin-4.1.6-3.3.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-4.1.19-3.8.2">
      <FullProductName ProductID="spacewalk-java-4.1.19-3.8.2">spacewalk-java-4.1.19-3.8.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-config-4.1.19-3.8.2">
      <FullProductName ProductID="spacewalk-java-config-4.1.19-3.8.2">spacewalk-java-config-4.1.19-3.8.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-lib-4.1.19-3.8.2">
      <FullProductName ProductID="spacewalk-java-lib-4.1.19-3.8.2">spacewalk-java-lib-4.1.19-3.8.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-postgresql-4.1.19-3.8.2">
      <FullProductName ProductID="spacewalk-java-postgresql-4.1.19-3.8.2">spacewalk-java-postgresql-4.1.19-3.8.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-setup-4.1.6-3.3.2">
      <FullProductName ProductID="spacewalk-setup-4.1.6-3.3.2">spacewalk-setup-4.1.6-3.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-taskomatic-4.1.19-3.8.2">
      <FullProductName ProductID="spacewalk-taskomatic-4.1.19-3.8.2">spacewalk-taskomatic-4.1.19-3.8.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="google-gson-javadoc-2.8.5-3.4.3">
      <FullProductName ProductID="google-gson-javadoc-2.8.5-3.4.3">google-gson-javadoc-2.8.5-3.4.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="httpcomponents-client-cache-4.5.6-3.4.2">
      <FullProductName ProductID="httpcomponents-client-cache-4.5.6-3.4.2">httpcomponents-client-cache-4.5.6-3.4.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="httpcomponents-client-javadoc-4.5.6-3.4.2">
      <FullProductName ProductID="httpcomponents-client-javadoc-4.5.6-3.4.2">httpcomponents-client-javadoc-4.5.6-3.4.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="httpcomponents-core-javadoc-4.4.10-3.4.2">
      <FullProductName ProductID="httpcomponents-core-javadoc-4.4.10-3.4.2">httpcomponents-core-javadoc-4.4.10-3.4.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-java-apidoc-sources-4.1.19-3.8.2">
      <FullProductName ProductID="spacewalk-java-apidoc-sources-4.1.19-3.8.2">spacewalk-java-apidoc-sources-4.1.19-3.8.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="velocity-1.7-11.4.3">
      <FullProductName ProductID="velocity-1.7-11.4.3">velocity-1.7-11.4.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="velocity-demo-1.7-11.4.3">
      <FullProductName ProductID="velocity-demo-1.7-11.4.3">velocity-demo-1.7-11.4.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="velocity-javadoc-1.7-11.4.3">
      <FullProductName ProductID="velocity-javadoc-1.7-11.4.3">velocity-javadoc-1.7-11.4.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="velocity-manual-1.7-11.4.3">
      <FullProductName ProductID="velocity-manual-1.7-11.4.3">velocity-manual-1.7-11.4.3</FullProductName>
    </Branch>
    <Relationship ProductReference="google-gson-2.8.5-3.4.3" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:google-gson-2.8.5-3.4.3">google-gson-2.8.5-3.4.3 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-client-4.5.6-3.4.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:httpcomponents-client-4.5.6-3.4.2">httpcomponents-client-4.5.6-3.4.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-core-4.4.10-3.4.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:httpcomponents-core-4.4.10-3.4.2">httpcomponents-core-4.4.10-3.4.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="salt-netapi-client-0.17.0-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:salt-netapi-client-0.17.0-3.3.2">salt-netapi-client-0.17.0-3.3.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-admin-4.1.6-3.3.3" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-admin-4.1.6-3.3.3">spacewalk-admin-4.1.6-3.3.3 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-4.1.19-3.8.2">spacewalk-java-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-config-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-config-4.1.19-3.8.2">spacewalk-java-config-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-lib-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-lib-4.1.19-3.8.2">spacewalk-java-lib-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-postgresql-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-postgresql-4.1.19-3.8.2">spacewalk-java-postgresql-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-setup-4.1.6-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-setup-4.1.6-3.3.2">spacewalk-setup-4.1.6-3.3.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-taskomatic-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-taskomatic-4.1.19-3.8.2">spacewalk-taskomatic-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure</FullProductName>
    </Relationship>
    <Relationship ProductReference="google-gson-2.8.5-3.4.3" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:google-gson-2.8.5-3.4.3">google-gson-2.8.5-3.4.3 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-client-4.5.6-3.4.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:httpcomponents-client-4.5.6-3.4.2">httpcomponents-client-4.5.6-3.4.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-core-4.4.10-3.4.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:httpcomponents-core-4.4.10-3.4.2">httpcomponents-core-4.4.10-3.4.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="salt-netapi-client-0.17.0-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:salt-netapi-client-0.17.0-3.3.2">salt-netapi-client-0.17.0-3.3.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-admin-4.1.6-3.3.3" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-admin-4.1.6-3.3.3">spacewalk-admin-4.1.6-3.3.3 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-4.1.19-3.8.2">spacewalk-java-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-config-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-config-4.1.19-3.8.2">spacewalk-java-config-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-lib-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-lib-4.1.19-3.8.2">spacewalk-java-lib-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-postgresql-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-postgresql-4.1.19-3.8.2">spacewalk-java-postgresql-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-setup-4.1.6-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-setup-4.1.6-3.3.2">spacewalk-setup-4.1.6-3.3.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-taskomatic-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-taskomatic-4.1.19-3.8.2">spacewalk-taskomatic-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM</FullProductName>
    </Relationship>
    <Relationship ProductReference="google-gson-2.8.5-3.4.3" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:google-gson-2.8.5-3.4.3">google-gson-2.8.5-3.4.3 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-client-4.5.6-3.4.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:httpcomponents-client-4.5.6-3.4.2">httpcomponents-client-4.5.6-3.4.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-core-4.4.10-3.4.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:httpcomponents-core-4.4.10-3.4.2">httpcomponents-core-4.4.10-3.4.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="salt-netapi-client-0.17.0-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:salt-netapi-client-0.17.0-3.3.2">salt-netapi-client-0.17.0-3.3.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-admin-4.1.6-3.3.3" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-admin-4.1.6-3.3.3">spacewalk-admin-4.1.6-3.3.3 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-4.1.19-3.8.2">spacewalk-java-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-config-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-config-4.1.19-3.8.2">spacewalk-java-config-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-lib-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-lib-4.1.19-3.8.2">spacewalk-java-lib-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-postgresql-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-postgresql-4.1.19-3.8.2">spacewalk-java-postgresql-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-setup-4.1.6-3.3.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-setup-4.1.6-3.3.2">spacewalk-setup-4.1.6-3.3.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-taskomatic-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE">
      <FullProductName ProductID="Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-taskomatic-4.1.19-3.8.2">spacewalk-taskomatic-4.1.19-3.8.2 as a component of Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE</FullProductName>
    </Relationship>
    <Relationship ProductReference="google-gson-2.8.5-3.4.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:google-gson-2.8.5-3.4.3">google-gson-2.8.5-3.4.3 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-client-4.5.6-3.4.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:httpcomponents-client-4.5.6-3.4.2">httpcomponents-client-4.5.6-3.4.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="httpcomponents-core-4.4.10-3.4.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:httpcomponents-core-4.4.10-3.4.2">httpcomponents-core-4.4.10-3.4.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="salt-netapi-client-0.17.0-3.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:salt-netapi-client-0.17.0-3.3.2">salt-netapi-client-0.17.0-3.3.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-admin-4.1.6-3.3.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:spacewalk-admin-4.1.6-3.3.3">spacewalk-admin-4.1.6-3.3.3 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:spacewalk-java-4.1.19-3.8.2">spacewalk-java-4.1.19-3.8.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-config-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:spacewalk-java-config-4.1.19-3.8.2">spacewalk-java-config-4.1.19-3.8.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-lib-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:spacewalk-java-lib-4.1.19-3.8.2">spacewalk-java-lib-4.1.19-3.8.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-java-postgresql-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:spacewalk-java-postgresql-4.1.19-3.8.2">spacewalk-java-postgresql-4.1.19-3.8.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-setup-4.1.6-3.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:spacewalk-setup-4.1.6-3.3.2">spacewalk-setup-4.1.6-3.3.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-taskomatic-4.1.19-3.8.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.1">
      <FullProductName ProductID="SUSE Manager Server Module 4.1:spacewalk-taskomatic-4.1.19-3.8.2">spacewalk-taskomatic-4.1.19-3.8.2 as a component of SUSE Manager Server Module 4.1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE Manager Server 3.2, SUSE Manager Server 4.0 allows local users to escalate to root on every system managed by SUSE manager. On the managing node itself code can be executed as user salt, potentially allowing for escalation to root there. This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.1 google-gson versions prior to 2.8.5-3.4.3, httpcomponents-client-4.5.6-3.4.2, httpcomponents-. SUSE Manager Proxy 4.0 release-notes-susemanager-proxy versions prior to 4.0.9-0.16.38.1. SUSE Manager Retail Branch Server 4.0 release-notes-susemanager-proxy versions prior to 4.0.9-0.16.38.1. SUSE Manager Server 3.2 salt-netapi-client versions prior to 0.16.0-4.14.1, spacewalk-. SUSE Manager Server 4.0 release-notes-susemanager versions prior to 4.0.9-3.54.1.</Note>
    </Notes>
    <CVE>CVE-2020-8028</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:google-gson-2.8.5-3.4.3</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:httpcomponents-client-4.5.6-3.4.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:httpcomponents-core-4.4.10-3.4.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:salt-netapi-client-0.17.0-3.3.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-admin-4.1.6-3.3.3</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-config-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-lib-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-java-postgresql-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-setup-4.1.6-3.3.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure:spacewalk-taskomatic-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:google-gson-2.8.5-3.4.3</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:httpcomponents-client-4.5.6-3.4.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:httpcomponents-core-4.4.10-3.4.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:salt-netapi-client-0.17.0-3.3.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-admin-4.1.6-3.3.3</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-config-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-lib-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-java-postgresql-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-setup-4.1.6-3.3.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM:spacewalk-taskomatic-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:google-gson-2.8.5-3.4.3</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:httpcomponents-client-4.5.6-3.4.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:httpcomponents-core-4.4.10-3.4.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:salt-netapi-client-0.17.0-3.3.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-admin-4.1.6-3.3.3</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-config-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-lib-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-java-postgresql-4.1.19-3.8.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-setup-4.1.6-3.3.2</ProductID>
        <ProductID>Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE:spacewalk-taskomatic-4.1.19-3.8.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:google-gson-2.8.5-3.4.3</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:httpcomponents-client-4.5.6-3.4.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:httpcomponents-core-4.4.10-3.4.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:salt-netapi-client-0.17.0-3.3.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:spacewalk-admin-4.1.6-3.3.3</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:spacewalk-java-4.1.19-3.8.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:spacewalk-java-config-4.1.19-3.8.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:spacewalk-java-lib-4.1.19-3.8.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:spacewalk-java-postgresql-4.1.19-3.8.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:spacewalk-setup-4.1.6-3.3.2</ProductID>
        <ProductID>SUSE Manager Server Module 4.1:spacewalk-taskomatic-4.1.19-3.8.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2020/suse-su-20202647-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8028.html</URL>
        <Description>CVE-2020-8028</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175884</URL>
        <Description>SUSE Bug 1175884</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
