{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"important"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2016-9587","title":"Title"},{"category":"description","text":"Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2016-9587","url":"https://www.suse.com/security/cve/CVE-2016-9587"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1019021 for CVE-2016-9587","url":"https://bugzilla.suse.com/1019021"},{"category":"external","summary":"Advisory link for SUSE-SU-2017:3029-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2017-November/003400.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2020:3309-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2020-November/007763.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2024:1427-1","url":"https://lists.suse.com/pipermail/sle-updates/2024-April/035080.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2024:1509-1","url":"https://lists.suse.com/pipermail/sle-updates/2024-May/035168.html"},{"category":"external","summary":"Advisory link for openSUSE-SU-2024:14536-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7LWEIR2LXW4QRWCY6HDMLUO2OTX5OZIC/"}],"title":"SUSE CVE CVE-2016-9587","tracking":{"current_release_date":"2026-03-16T17:41:09Z","generator":{"date":"2023-02-15T04:55:30Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2016-9587","initial_release_date":"2023-02-15T04:55:30Z","revision_history":[{"date":"2023-02-15T04:55:30Z","number":"2","summary":"Current version"},{"date":"2023-12-08T04:30:50Z","number":"3","summary":"Current version"},{"date":"2024-04-24T23:59:37Z","number":"4","summary":"Current version"},{"date":"2024-05-07T03:27:31Z","number":"5","summary":"Current version"},{"date":"2024-06-13T05:45:09Z","number":"6","summary":"Current version"},{"date":"2024-06-15T03:59:36Z","number":"7","summary":"Current version"},{"date":"2024-08-09T03:00:55Z","number":"8","summary":"Current version"},{"date":"2024-11-16T02:19:15Z","number":"9","summary":"Current version"},{"date":"2024-12-03T03:04:31Z","number":"10","summary":"Current version"},{"date":"2024-12-05T02:19:58Z","number":"11","summary":"Current version"},{"date":"2025-01-01T09:28:20Z","number":"12","summary":"Current version"},{"date":"2025-02-18T15:35:30Z","number":"13","summary":"Current version"},{"date":"2025-03-14T05:21:34Z","number":"14","summary":"Current version"},{"date":"2025-03-16T03:36:54Z","number":"15","summary":"Current version"},{"date":"2025-04-08T02:52:17Z","number":"16","summary":"Current version"},{"date":"2025-05-01T06:39:30Z","number":"17","summary":"Current version"},{"date":"2025-05-16T03:12:55Z","number":"18","summary":"Current version"},{"date":"2025-06-26T05:39:09Z","number":"19","summary":"Current version"},{"date":"2025-08-20T23:43:22Z","number":"20","summary":"Current version"},{"date":"2025-10-08T23:46:34Z","number":"21","summary":"Current version"},{"date":"2025-11-04T02:50:38Z","number":"22","summary":"Current version"},{"date":"2025-11-22T00:38:27Z","number":"23","summary":"Current version"},{"date":"2026-03-15T12:18:25Z","number":"24","summary":"unknown changes"},{"date":"2026-03-16T17:41:09Z","number":"25","summary":"unknown changes"}],"status":"interim","version":"25"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"HPE Helion OpenStack 8","product":{"name":"HPE Helion OpenStack 8","product_id":"HPE Helion OpenStack 8","product_identification_helper":{"cpe":"cpe:/o:suse:hpe-helion-openstack:8"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 11 SP3-TERADATA","product":{"name":"SUSE Linux Enterprise Server 11 SP3-TERADATA","product_id":"SUSE Linux Enterprise Server 11 SP3-TERADATA","product_identification_helper":{"cpe":"cpe:/o:suse:sles:11:sp3:teradata"}}},{"category":"product_name","name":"SUSE Linux Enterprise Server 16.0","product":{"name":"SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0","product_identification_helper":{"cpe":"cpe:/o:suse:sles:16:16.0:server"}}},{"category":"product_name","name":"SUSE Manager Client Tools 15","product":{"name":"SUSE Manager Client Tools 15","product_id":"SUSE Manager Client Tools 15"}},{"category":"product_name","name":"SUSE Manager Client Tools 15-BETA","product":{"name":"SUSE Manager Client Tools 15-BETA","product_id":"SUSE Manager Client Tools 15-BETA"}},{"category":"product_name","name":"SUSE Manager Proxy Module 4.3","product":{"name":"SUSE Manager Proxy Module 4.3","product_id":"SUSE Manager Proxy Module 4.3","product_identification_helper":{"cpe":"cpe:/o:suse:sle-module-suse-manager-proxy:4.3"}}},{"category":"product_name","name":"SUSE OpenStack Cloud 7","product":{"name":"SUSE OpenStack Cloud 7","product_id":"SUSE OpenStack Cloud 7","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud:7"}}},{"category":"product_name","name":"SUSE OpenStack Cloud 8","product":{"name":"SUSE OpenStack Cloud 8","product_id":"SUSE OpenStack Cloud 8","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud:8"}}},{"category":"product_name","name":"SUSE OpenStack Cloud Crowbar 8","product":{"name":"SUSE OpenStack Cloud Crowbar 8","product_id":"SUSE OpenStack Cloud Crowbar 8","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud-crowbar:8"}}},{"category":"product_name","name":"SUSE Package Hub 12","product":{"name":"SUSE Package Hub 12","product_id":"SUSE Package Hub 12","product_identification_helper":{"cpe":"cpe:/o:suse:packagehub:12"}}},{"category":"product_name","name":"openSUSE Leap 15.5","product":{"name":"openSUSE Leap 15.5","product_id":"openSUSE Leap 15.5","product_identification_helper":{"cpe":"cpe:/o:opensuse:leap:15.5"}}},{"category":"product_name","name":"openSUSE Tumbleweed","product":{"name":"openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed","product_identification_helper":{"cpe":"cpe:/o:opensuse:tumbleweed"}}},{"category":"product_version","name":"ansible-10-10.6.0-1.1","product":{"name":"ansible-10-10.6.0-1.1","product_id":"ansible-10-10.6.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/ansible-10@10.6.0-1.1"}}},{"category":"product_version","name":"ansible-11-11.11.0-1.1","product":{"name":"ansible-11-11.11.0-1.1","product_id":"ansible-11-11.11.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/ansible-11@11.11.0-1.1"}}},{"category":"product_version","name":"ansible-11.3.0-160000.3.2","product":{"name":"ansible-11.3.0-160000.3.2","product_id":"ansible-11.3.0-160000.3.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:11.3.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@11.3.0-160000.3.2?upstream=ansible-11.3.0-160000.3.2.src.rpm"}}},{"category":"product_version","name":"ansible-12-12.2.0-1.1","product":{"name":"ansible-12-12.2.0-1.1","product_id":"ansible-12-12.2.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/ansible-12@12.2.0-1.1"}}},{"category":"product_version","name":"ansible-2.2.0.0-7.1","product":{"name":"ansible-2.2.0.0-7.1","product_id":"ansible-2.2.0.0-7.1","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.2.0.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@2.2.0.0-7.1?upstream=ansible-2.2.0.0-7.1.src.rpm"}}},{"category":"product_version","name":"ansible-2.2.3.0-5.1","product":{"name":"ansible-2.2.3.0-5.1","product_id":"ansible-2.2.3.0-5.1","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.2.3.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@2.2.3.0-5.1?upstream=ansible-2.2.3.0-5.1.src.rpm"}}},{"category":"product_version","name":"ansible-2.4.1.0-6.1","product":{"name":"ansible-2.4.1.0-6.1","product_id":"ansible-2.4.1.0-6.1","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.4.1.0:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@2.4.1.0-6.1?upstream=ansible-2.4.1.0-6.1.src.rpm"}}},{"category":"product_version","name":"ansible-2.9.14-3.15.1","product":{"name":"ansible-2.9.14-3.15.1","product_id":"ansible-2.9.14-3.15.1","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.14:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@2.9.14-3.15.1?upstream=ansible-2.9.14-3.15.1.src.rpm"}}},{"category":"product_version","name":"ansible-2.9.24-1.2","product":{"name":"ansible-2.9.24-1.2","product_id":"ansible-2.9.24-1.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.24:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@2.9.24-1.2?upstream=ansible-2.9.24-1.2.src.rpm"}}},{"category":"product_version","name":"ansible-2.9.27-150000.1.17.2","product":{"name":"ansible-2.9.27-150000.1.17.2","product_id":"ansible-2.9.27-150000.1.17.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.27:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@2.9.27-150000.1.17.2?upstream=ansible-2.9.27-150000.1.17.2.src.rpm"}}},{"category":"product_version","name":"ansible-2.9.27-159000.3.12.2","product":{"name":"ansible-2.9.27-159000.3.12.2","product_id":"ansible-2.9.27-159000.3.12.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.27:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible@2.9.27-159000.3.12.2?upstream=ansible-2.9.27-159000.3.12.2.src.rpm"}}},{"category":"product_version","name":"ansible-9-9.8.0-1.1","product":{"name":"ansible-9-9.8.0-1.1","product_id":"ansible-9-9.8.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/ansible-9@9.8.0-1.1"}}},{"category":"product_version","name":"ansible-doc-2.9.24-1.2","product":{"name":"ansible-doc-2.9.24-1.2","product_id":"ansible-doc-2.9.24-1.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.24:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible-doc@2.9.24-1.2?upstream=ansible-2.9.24-1.2.src.rpm"}}},{"category":"product_version","name":"ansible-doc-2.9.27-150000.1.17.2","product":{"name":"ansible-doc-2.9.27-150000.1.17.2","product_id":"ansible-doc-2.9.27-150000.1.17.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.27:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible-doc@2.9.27-150000.1.17.2?upstream=ansible-2.9.27-150000.1.17.2.src.rpm"}}},{"category":"product_version","name":"ansible-doc-2.9.27-159000.3.12.2","product":{"name":"ansible-doc-2.9.27-159000.3.12.2","product_id":"ansible-doc-2.9.27-159000.3.12.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.27:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible-doc@2.9.27-159000.3.12.2?upstream=ansible-2.9.27-159000.3.12.2.src.rpm"}}},{"category":"product_version","name":"ansible-test-2.9.24-1.2","product":{"name":"ansible-test-2.9.24-1.2","product_id":"ansible-test-2.9.24-1.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.24:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible-test@2.9.24-1.2?upstream=ansible-2.9.24-1.2.src.rpm"}}},{"category":"product_version","name":"ansible-test-2.9.27-150000.1.17.2","product":{"name":"ansible-test-2.9.27-150000.1.17.2","product_id":"ansible-test-2.9.27-150000.1.17.2","product_identification_helper":{"cpe":"cpe:2.3:a:redhat:ansible:2.9.27:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/ansible-test@2.9.27-150000.1.17.2?upstream=ansible-2.9.27-150000.1.17.2.src.rpm"}}},{"category":"product_version","name":"ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","product":{"name":"ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","product_id":"ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","product_identification_helper":{"purl":"pkg:rpm/suse/ardana-ansible@8.0+git.1596735237.54109b1-3.77.1?upstream=ardana-ansible-8.0+git.1596735237.54109b1-3.77.1.src.rpm"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.14-3.15.1 as component of HPE Helion OpenStack 8","product_id":"HPE Helion OpenStack 8:ansible-2.9.14-3.15.1"},"product_reference":"ansible-2.9.14-3.15.1","relates_to_product_reference":"HPE Helion OpenStack 8"},{"category":"default_component_of","full_product_name":{"name":"ardana-ansible-8.0+git.1596735237.54109b1-3.77.1 as component of HPE Helion OpenStack 8","product_id":"HPE Helion OpenStack 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1"},"product_reference":"ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","relates_to_product_reference":"HPE Helion OpenStack 8"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.2.0.0-7.1 as component of SUSE Linux Enterprise Server 11 SP3-TERADATA","product_id":"SUSE Linux Enterprise Server 11 SP3-TERADATA:ansible-2.2.0.0-7.1"},"product_reference":"ansible-2.2.0.0-7.1","relates_to_product_reference":"SUSE Linux Enterprise Server 11 SP3-TERADATA"},{"category":"default_component_of","full_product_name":{"name":"ansible-11.3.0-160000.3.2 as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:ansible-11.3.0-160000.3.2"},"product_reference":"ansible-11.3.0-160000.3.2","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.27-150000.1.17.2 as component of SUSE Manager Client Tools 15","product_id":"SUSE Manager Client Tools 15:ansible-2.9.27-150000.1.17.2"},"product_reference":"ansible-2.9.27-150000.1.17.2","relates_to_product_reference":"SUSE Manager Client Tools 15"},{"category":"default_component_of","full_product_name":{"name":"ansible-doc-2.9.27-150000.1.17.2 as component of SUSE Manager Client Tools 15","product_id":"SUSE Manager Client Tools 15:ansible-doc-2.9.27-150000.1.17.2"},"product_reference":"ansible-doc-2.9.27-150000.1.17.2","relates_to_product_reference":"SUSE Manager Client Tools 15"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.27-159000.3.12.2 as component of SUSE Manager Client Tools 15-BETA","product_id":"SUSE Manager Client Tools 15-BETA:ansible-2.9.27-159000.3.12.2"},"product_reference":"ansible-2.9.27-159000.3.12.2","relates_to_product_reference":"SUSE Manager Client Tools 15-BETA"},{"category":"default_component_of","full_product_name":{"name":"ansible-doc-2.9.27-159000.3.12.2 as component of SUSE Manager Client Tools 15-BETA","product_id":"SUSE Manager Client Tools 15-BETA:ansible-doc-2.9.27-159000.3.12.2"},"product_reference":"ansible-doc-2.9.27-159000.3.12.2","relates_to_product_reference":"SUSE Manager Client Tools 15-BETA"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.27-150000.1.17.2 as component of SUSE Manager Proxy Module 4.3","product_id":"SUSE Manager Proxy Module 4.3:ansible-2.9.27-150000.1.17.2"},"product_reference":"ansible-2.9.27-150000.1.17.2","relates_to_product_reference":"SUSE Manager Proxy Module 4.3"},{"category":"default_component_of","full_product_name":{"name":"ansible-doc-2.9.27-150000.1.17.2 as component of SUSE Manager Proxy Module 4.3","product_id":"SUSE Manager Proxy Module 4.3:ansible-doc-2.9.27-150000.1.17.2"},"product_reference":"ansible-doc-2.9.27-150000.1.17.2","relates_to_product_reference":"SUSE Manager Proxy Module 4.3"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.2.3.0-5.1 as component of SUSE OpenStack Cloud 7","product_id":"SUSE OpenStack Cloud 7:ansible-2.2.3.0-5.1"},"product_reference":"ansible-2.2.3.0-5.1","relates_to_product_reference":"SUSE OpenStack Cloud 7"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.14-3.15.1 as component of SUSE OpenStack Cloud 8","product_id":"SUSE OpenStack Cloud 8:ansible-2.9.14-3.15.1"},"product_reference":"ansible-2.9.14-3.15.1","relates_to_product_reference":"SUSE OpenStack Cloud 8"},{"category":"default_component_of","full_product_name":{"name":"ardana-ansible-8.0+git.1596735237.54109b1-3.77.1 as component of SUSE OpenStack Cloud 8","product_id":"SUSE OpenStack Cloud 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1"},"product_reference":"ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","relates_to_product_reference":"SUSE OpenStack Cloud 8"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.14-3.15.1 as component of SUSE OpenStack Cloud Crowbar 8","product_id":"SUSE OpenStack Cloud Crowbar 8:ansible-2.9.14-3.15.1"},"product_reference":"ansible-2.9.14-3.15.1","relates_to_product_reference":"SUSE OpenStack Cloud Crowbar 8"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.4.1.0-6.1 as component of SUSE Package Hub 12","product_id":"SUSE Package Hub 12:ansible-2.4.1.0-6.1"},"product_reference":"ansible-2.4.1.0-6.1","relates_to_product_reference":"SUSE Package Hub 12"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.27-150000.1.17.2 as component of openSUSE Leap 15.5","product_id":"openSUSE Leap 15.5:ansible-2.9.27-150000.1.17.2"},"product_reference":"ansible-2.9.27-150000.1.17.2","relates_to_product_reference":"openSUSE Leap 15.5"},{"category":"default_component_of","full_product_name":{"name":"ansible-doc-2.9.27-150000.1.17.2 as component of openSUSE Leap 15.5","product_id":"openSUSE Leap 15.5:ansible-doc-2.9.27-150000.1.17.2"},"product_reference":"ansible-doc-2.9.27-150000.1.17.2","relates_to_product_reference":"openSUSE Leap 15.5"},{"category":"default_component_of","full_product_name":{"name":"ansible-test-2.9.27-150000.1.17.2 as component of openSUSE Leap 15.5","product_id":"openSUSE Leap 15.5:ansible-test-2.9.27-150000.1.17.2"},"product_reference":"ansible-test-2.9.27-150000.1.17.2","relates_to_product_reference":"openSUSE Leap 15.5"},{"category":"default_component_of","full_product_name":{"name":"ansible-2.9.24-1.2 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:ansible-2.9.24-1.2"},"product_reference":"ansible-2.9.24-1.2","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"ansible-10-10.6.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:ansible-10-10.6.0-1.1"},"product_reference":"ansible-10-10.6.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"ansible-11-11.11.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:ansible-11-11.11.0-1.1"},"product_reference":"ansible-11-11.11.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"ansible-12-12.2.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:ansible-12-12.2.0-1.1"},"product_reference":"ansible-12-12.2.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"ansible-9-9.8.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:ansible-9-9.8.0-1.1"},"product_reference":"ansible-9-9.8.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"ansible-doc-2.9.24-1.2 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:ansible-doc-2.9.24-1.2"},"product_reference":"ansible-doc-2.9.24-1.2","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"ansible-test-2.9.24-1.2 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:ansible-test-2.9.24-1.2"},"product_reference":"ansible-test-2.9.24-1.2","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"ansible1 as component of HPE Helion OpenStack 8","product_id":"HPE Helion OpenStack 8:ansible1"},"product_reference":"ansible1","relates_to_product_reference":"HPE Helion OpenStack 8"},{"category":"default_component_of","full_product_name":{"name":"ansible as component of SUSE Manager Proxy Module 4.2","product_id":"SUSE Manager Proxy Module 4.2:ansible"},"product_reference":"ansible","relates_to_product_reference":"SUSE Manager Proxy Module 4.2"},{"category":"default_component_of","full_product_name":{"name":"ansible-doc as component of SUSE Manager Proxy Module 4.2","product_id":"SUSE Manager Proxy Module 4.2:ansible-doc"},"product_reference":"ansible-doc","relates_to_product_reference":"SUSE Manager Proxy Module 4.2"},{"category":"default_component_of","full_product_name":{"name":"ansible1 as component of SUSE OpenStack Cloud 8","product_id":"SUSE OpenStack Cloud 8:ansible1"},"product_reference":"ansible1","relates_to_product_reference":"SUSE OpenStack Cloud 8"}]},"vulnerabilities":[{"cve":"CVE-2016-9587","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2016-9587"}],"notes":[{"category":"general","text":"Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.","title":"CVE description"}],"product_status":{"recommended":["HPE Helion OpenStack 8:ansible-2.9.14-3.15.1","HPE Helion OpenStack 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-2.9.27-150000.1.17.2","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-doc-2.9.27-150000.1.17.2","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-test-2.9.27-150000.1.17.2","SUSE Linux Enterprise Server 11 SP3-TERADATA:ansible-2.2.0.0-7.1","SUSE Linux Enterprise Server 16.0:ansible-11.3.0-160000.3.2","SUSE Manager Client Tools 15-BETA:ansible-2.9.27-159000.3.12.2","SUSE Manager Client Tools 15-BETA:ansible-doc-2.9.27-159000.3.12.2","SUSE Manager Client Tools 15:ansible-2.9.27-150000.1.17.2","SUSE Manager Client Tools 15:ansible-doc-2.9.27-150000.1.17.2","SUSE Manager Proxy Module 4.3:ansible-2.9.27-150000.1.17.2","SUSE Manager Proxy Module 4.3:ansible-doc-2.9.27-150000.1.17.2","SUSE OpenStack Cloud 7:ansible-2.2.3.0-5.1","SUSE OpenStack Cloud 8:ansible-2.9.14-3.15.1","SUSE OpenStack Cloud 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","SUSE OpenStack Cloud Crowbar 8:ansible-2.9.14-3.15.1","SUSE Package Hub 12:ansible-2.4.1.0-6.1","openSUSE Leap 15.5:ansible-2.9.27-150000.1.17.2","openSUSE Leap 15.5:ansible-doc-2.9.27-150000.1.17.2","openSUSE Leap 15.5:ansible-test-2.9.27-150000.1.17.2","openSUSE Tumbleweed:ansible-10-10.6.0-1.1","openSUSE Tumbleweed:ansible-11-11.11.0-1.1","openSUSE Tumbleweed:ansible-12-12.2.0-1.1","openSUSE Tumbleweed:ansible-2.9.24-1.2","openSUSE Tumbleweed:ansible-9-9.8.0-1.1","openSUSE Tumbleweed:ansible-doc-2.9.24-1.2","openSUSE Tumbleweed:ansible-test-2.9.24-1.2"]},"references":[{"category":"external","summary":"CVE-2016-9587","url":"https://www.suse.com/security/cve/CVE-2016-9587"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1019021 for CVE-2016-9587","url":"https://bugzilla.suse.com/1019021"},{"category":"external","summary":"Advisory link for SUSE-SU-2017:3029-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2017-November/003400.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2020:3309-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2020-November/007763.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2024:1427-1","url":"https://lists.suse.com/pipermail/sle-updates/2024-April/035080.html"},{"category":"external","summary":"Advisory link for SUSE-SU-2024:1509-1","url":"https://lists.suse.com/pipermail/sle-updates/2024-May/035168.html"},{"category":"external","summary":"Advisory link for openSUSE-SU-2024:14536-1","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7LWEIR2LXW4QRWCY6HDMLUO2OTX5OZIC/"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["HPE Helion OpenStack 8:ansible-2.9.14-3.15.1","HPE Helion OpenStack 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-2.9.27-150000.1.17.2","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-doc-2.9.27-150000.1.17.2","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-test-2.9.27-150000.1.17.2","SUSE Linux Enterprise Server 11 SP3-TERADATA:ansible-2.2.0.0-7.1","SUSE Linux Enterprise Server 16.0:ansible-11.3.0-160000.3.2","SUSE Manager Client Tools 15-BETA:ansible-2.9.27-159000.3.12.2","SUSE Manager Client Tools 15-BETA:ansible-doc-2.9.27-159000.3.12.2","SUSE Manager Client Tools 15:ansible-2.9.27-150000.1.17.2","SUSE Manager Client Tools 15:ansible-doc-2.9.27-150000.1.17.2","SUSE Manager Proxy Module 4.3:ansible-2.9.27-150000.1.17.2","SUSE Manager Proxy Module 4.3:ansible-doc-2.9.27-150000.1.17.2","SUSE OpenStack Cloud 7:ansible-2.2.3.0-5.1","SUSE OpenStack Cloud 8:ansible-2.9.14-3.15.1","SUSE OpenStack Cloud 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","SUSE OpenStack Cloud Crowbar 8:ansible-2.9.14-3.15.1","SUSE Package Hub 12:ansible-2.4.1.0-6.1","openSUSE Leap 15.5:ansible-2.9.27-150000.1.17.2","openSUSE Leap 15.5:ansible-doc-2.9.27-150000.1.17.2","openSUSE Leap 15.5:ansible-test-2.9.27-150000.1.17.2","openSUSE Tumbleweed:ansible-10-10.6.0-1.1","openSUSE Tumbleweed:ansible-11-11.11.0-1.1","openSUSE Tumbleweed:ansible-12-12.2.0-1.1","openSUSE Tumbleweed:ansible-2.9.24-1.2","openSUSE Tumbleweed:ansible-9-9.8.0-1.1","openSUSE Tumbleweed:ansible-doc-2.9.24-1.2","openSUSE Tumbleweed:ansible-test-2.9.24-1.2"]},{"category":"no_fix_planned","details":"There is no fix planned for these products.\n","product_ids":["HPE Helion OpenStack 8:ansible1","SUSE Manager Proxy Module 4.2:ansible","SUSE Manager Proxy Module 4.2:ansible-doc","SUSE OpenStack Cloud 8:ansible1"]}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.0"},"products":["HPE Helion OpenStack 8:ansible-2.9.14-3.15.1","HPE Helion OpenStack 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-2.9.27-150000.1.17.2","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-doc-2.9.27-150000.1.17.2","SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7:ansible-test-2.9.27-150000.1.17.2","SUSE Linux Enterprise Server 11 SP3-TERADATA:ansible-2.2.0.0-7.1","SUSE Linux Enterprise Server 16.0:ansible-11.3.0-160000.3.2","SUSE Manager Client Tools 15-BETA:ansible-2.9.27-159000.3.12.2","SUSE Manager Client Tools 15-BETA:ansible-doc-2.9.27-159000.3.12.2","SUSE Manager Client Tools 15:ansible-2.9.27-150000.1.17.2","SUSE Manager Client Tools 15:ansible-doc-2.9.27-150000.1.17.2","SUSE Manager Proxy Module 4.3:ansible-2.9.27-150000.1.17.2","SUSE Manager Proxy Module 4.3:ansible-doc-2.9.27-150000.1.17.2","SUSE OpenStack Cloud 7:ansible-2.2.3.0-5.1","SUSE OpenStack Cloud 8:ansible-2.9.14-3.15.1","SUSE OpenStack Cloud 8:ardana-ansible-8.0+git.1596735237.54109b1-3.77.1","SUSE OpenStack Cloud Crowbar 8:ansible-2.9.14-3.15.1","SUSE Package Hub 12:ansible-2.4.1.0-6.1","openSUSE Leap 15.5:ansible-2.9.27-150000.1.17.2","openSUSE Leap 15.5:ansible-doc-2.9.27-150000.1.17.2","openSUSE Leap 15.5:ansible-test-2.9.27-150000.1.17.2","openSUSE Tumbleweed:ansible-10-10.6.0-1.1","openSUSE Tumbleweed:ansible-11-11.11.0-1.1","openSUSE Tumbleweed:ansible-12-12.2.0-1.1","openSUSE Tumbleweed:ansible-2.9.24-1.2","openSUSE Tumbleweed:ansible-9-9.8.0-1.1","openSUSE Tumbleweed:ansible-doc-2.9.24-1.2","openSUSE Tumbleweed:ansible-test-2.9.24-1.2"]}],"threats":[{"category":"impact","date":"2017-01-10T04:15:16Z","details":"important"}],"title":"CVE-2016-9587"}]}