File _patchinfo of Package patchinfo.40880
<patchinfo incident="40880"> <category>security</category> <rating>important</rating> <packager>raulosuna</packager> <summary>Maintenance update for Multi-Linux Manager 4.3 LTS Release Notes Release Notes</summary> <description>Maintenance update for Multi-Linux Manager 4.3 LTS Release Notes Release Notes: This is a codestream only update </description> <releasetarget project="SUSE:SLE-15-SP4:Update"/> <issue tracker="ijsc" id="MSQA-1026"/> <issue tracker="cve" id="2025-53880"/> <issue tracker="cve" id="2025-53883"/> <issue tracker="cve" id="2025-53192"/> <issue tracker="bnc" id="1246439">L3: VUL-0: CVE-2025-53883: spacewalk-java: various XSS found on search page</issue> <issue tracker="bnc" id="1246277">VUL-0: CVE-2025-53880: susemanager-tftpsync-recv: arbitrary file creation and deletion due to path traversal</issue> <issue tracker="bnc" id="1248252">VUL-0: CVE-2025-53192: apache-commons-ognl: Expression Injection leading to RCE</issue> <issue tracker="bnc" id="1227577">VUL-0: spacecmd, susemanager, rhnlib and spacewalk-backend: usage of unsafe third party library for XML</issue> </patchinfo>