Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:4702 - Security Advisory
Issued:
2023-08-22
Updated:
2023-08-22

RHSA-2023:4702 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: subscription-manager security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for subscription-manager is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the Red Hat entitlement platform.

Security Fix(es):

  • subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration (CVE-2023-3899)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 2225407 - CVE-2023-3899 subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration

CVEs

  • CVE-2023-3899

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
subscription-manager-1.25.17.1-2.el8_1.src.rpm SHA-256: 7b9e528a9e35e21a2cce5dd3a9f1c29274f3801fa986b7e66120e6ed7278b1a6
ppc64le
dnf-plugin-subscription-manager-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: edfac5f32332217d14b7298d144d3b6545d017067da13a7e55b8ef64cd8f742d
dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 878c8ad673d6ea64cf3a78d366816683a9b72474b4e436f5c76c2930e1b1fe8c
dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 878c8ad673d6ea64cf3a78d366816683a9b72474b4e436f5c76c2930e1b1fe8c
python3-subscription-manager-rhsm-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: ee0a8295f1a99ceaa0c50f85b26d902e0b22e85808d4426e720120ab24bca383
python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 91169da80b187f2cf319cccba8b7281e488de9c2e9bb4ac51ab304be32cb1f40
python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 91169da80b187f2cf319cccba8b7281e488de9c2e9bb4ac51ab304be32cb1f40
python3-syspurpose-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: e955e3d742a3e9b1314366476d034832273c9c2744ef53c5020e9673ed9dd160
rhsm-gtk-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 571c75dd61f7e734281b150461ce3709d6f88c099db64176a17f725f8f26b52a
subscription-manager-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 14a89c6dae4286ca43b1d0c44990a179d99f6e4b347bf04d5febb3868230e2a6
subscription-manager-cockpit-1.25.17.1-2.el8_1.noarch.rpm SHA-256: 203b38f60c6f2fca355b86e9ff651e34ad66f45ee8c54d4941d63342a265e4e7
subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 2f2a945f018b228c394f1a3a04dd28c0ad6af879d37778ac5d0e5dc4a6637f67
subscription-manager-debuginfo-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 2f2a945f018b228c394f1a3a04dd28c0ad6af879d37778ac5d0e5dc4a6637f67
subscription-manager-debugsource-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 8843afedecc627c97717a1134c7ef3e91741f84f31736f13e68d299e1d8caff1
subscription-manager-debugsource-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 8843afedecc627c97717a1134c7ef3e91741f84f31736f13e68d299e1d8caff1
subscription-manager-initial-setup-addon-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 8fc16e4a35426234e164d3122346297435a941eddcb894353d66bb992c2ff87b
subscription-manager-migration-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 764ea67575adf767d241f3514affe3b657ca38da5e655e28ee4074e4eae87a79
subscription-manager-plugin-container-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 349941aadfd1f728c842c8917cb33ff175fcd1ee1deee00dacd17fb6534fb06b
subscription-manager-plugin-ostree-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 6e447517b7b037b182d384e6dc03f1668ee5e023ebc1c480af857c9928c6f6fe
subscription-manager-rhsm-certificates-1.25.17.1-2.el8_1.ppc64le.rpm SHA-256: 872ffeac2cf64aad177a8479f03bfefdae63aa5f080254a1376dc5eb839c7d96

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
subscription-manager-1.25.17.1-2.el8_1.src.rpm SHA-256: 7b9e528a9e35e21a2cce5dd3a9f1c29274f3801fa986b7e66120e6ed7278b1a6
x86_64
dnf-plugin-subscription-manager-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 6e76c3124f90dafee6e1b2617c90546cbfac65fea18015ba6c55e3c91ec5c5c3
dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 0bd861c8a13ae7a22386eca786e40f80aedabcb7377cb8dbc07928f082214418
dnf-plugin-subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 0bd861c8a13ae7a22386eca786e40f80aedabcb7377cb8dbc07928f082214418
python3-subscription-manager-rhsm-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 9d6bef8587e17f1a5fe5a29d870a599d4578907107f8ecbee578eb29bedad3ac
python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: caab5d073777f406b7a2a47c0d7e45315bc4803580c2f393bd0a6986bad3d83e
python3-subscription-manager-rhsm-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: caab5d073777f406b7a2a47c0d7e45315bc4803580c2f393bd0a6986bad3d83e
python3-syspurpose-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 487fa206be608d82189942c4e909fce5dfeea6007468b1f52872e694926f04de
rhsm-gtk-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 7a909b86ac388bfea2e851f1635f450fbe8ade2b20822afb9fb40ca6e0e19bf6
subscription-manager-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: e2d5fc017bb6ecc46060fff6f6673a7aa1bd7591fa8dac3c5eca9b4784657638
subscription-manager-cockpit-1.25.17.1-2.el8_1.noarch.rpm SHA-256: 203b38f60c6f2fca355b86e9ff651e34ad66f45ee8c54d4941d63342a265e4e7
subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 40b6c32ed849f0faa317d71b8997334c52949042fe3f08ab8f8596212e8ebb25
subscription-manager-debuginfo-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 40b6c32ed849f0faa317d71b8997334c52949042fe3f08ab8f8596212e8ebb25
subscription-manager-debugsource-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 21cbdbfcbbd1efc57e031c4e3c5e30f1d8c03ce24398f6c1a184cd02c13a8a44
subscription-manager-debugsource-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 21cbdbfcbbd1efc57e031c4e3c5e30f1d8c03ce24398f6c1a184cd02c13a8a44
subscription-manager-initial-setup-addon-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: af6d1c2076a7aa4ebf427c4bedeee1bff61e5b64517c88d1deeed7ee84eb7961
subscription-manager-migration-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 7133b94e6196c009e89d1d1249ee69d979b395a211a36f48952745500be3b897
subscription-manager-plugin-container-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 4f0560c79807eec9b4a414853748c93f3c15f453b4e1a9684c1664a48ed0733e
subscription-manager-plugin-ostree-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: 16f8fc1e3fe66c74a71922b337aa1153eadc704e85055deadb980c170a0d9985
subscription-manager-rhsm-certificates-1.25.17.1-2.el8_1.x86_64.rpm SHA-256: e5a28c3c27ded83f1b2a2933b391bccc63f6f93c50470031c58400480aa3796a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility