CVE-2025-46809
A Insertion of Sensitive Information into Log File vulnerability in SUSE Multi Linux Manager exposes the HTTP proxy credentials. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before 5.0.27-150600.3.33.1; Image SLES15-SP4-Manager-Server-4-3-BYOS: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2: from ? before 4.3.87-150400.3.110.2; Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE: from ? before 4.3.87-150400.3.110.2; SUSE Manager Server Module 4.3: from ? before 4.3.87-150400.3.110.2.
EPSS 0.14% · 34.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE | ? |
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2 | ? |
| SUSE | SUSE Manager Server Module 4.3 | ? |
| SUSE | SUSE Manager Proxy Module 4.3 | * |
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2 | * |
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE | ? |
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS | ? |
| SUSE | Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1 | ? |
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure | ? |
| SUSE | Image SLES15-SP4-Manager-Proxy-4-3-BYOS | * |
| SUSE | Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1 | ? |
| SUSE | Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure | ? |
| SUSE | Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 | ? |
Exploit Intelligence
- CIRCL seen: CVE-2025-46809 (circl-sighting)
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46809 (circl)
Timeline
- Jul 31, 2025 Coalition ESS Score
- Jul 31, 2025 CVE Published
- Jul 31, 2025 PoC Published
- Aug 1, 2025 EPSS Score
- Aug 10, 2025 EPSS Score
- Aug 18, 2025 EPSS Score
- Aug 26, 2025 Coalition ESS Score
- Aug 27, 2025 EPSS Score
- Sep 5, 2025 EPSS Score
- Sep 13, 2025 EPSS Score
- Sep 22, 2025 EPSS Score
- Oct 1, 2025 EPSS Score