---
id: CVE-2022-21952
title: >-
  A Missing Authentication for Critical Function vulnerability in spacewalk-java
  of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to
  easily exhaust available disk resources leading to DoS
summary: >-
  A Missing Authentication for Critical Function vulnerability in spacewalk-java
  of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to
  easily exhaust available disk resources leading to DoS. This issue affects:
  SUS…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-306
  - CWE-770
  - CWE-306
  - CWE-770
vendor: suse
product: manager_server
affected:
  - 'manager_server >= 4.1, < 4.1.46'
  - 'manager_server >= 4.2, < 4.2.37'
patched:
  - manager_server 4.2.37
published: '2022-06-22'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-21952'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1199512'
    label: meissner@suse.de
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=1199512'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01546
epssPercentile: 0.73909
ingestedAt: '2026-07-07T10:52:44.248Z'
---

## Overview

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.

## Affected

- `manager_server >= 4.1, < 4.1.46`
- `manager_server >= 4.2, < 4.2.37`

## Remediation

Upgrade past the affected range:

- `manager_server 4.2.37`
