Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:4704 - Security Advisory
Issued:
2023-08-22
Updated:
2023-08-22

RHSA-2023:4704 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: subscription-manager security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for subscription-manager is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the Red Hat entitlement platform.

Security Fix(es):

  • subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration (CVE-2023-3899)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.4 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4 x86_64

Fixes

  • BZ - 2225407 - CVE-2023-3899 subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration

CVEs

  • CVE-2023-3899

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
subscription-manager-1.28.13-7.el8_4.src.rpm SHA-256: 04973de1a074fb1f5cf95e5e0bfa3d3d1220878f680003beb9040dbfacdc6f5d
x86_64
dnf-plugin-subscription-manager-1.28.13-7.el8_4.x86_64.rpm SHA-256: 5cde4beed5eb6437f3922a84332bf7155dcc8fa51966486632c9544c25814269
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 62893307c13f45e18c706dae675b43400b7385ac1ee2cf8c60158a5bd7fb02ae
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 62893307c13f45e18c706dae675b43400b7385ac1ee2cf8c60158a5bd7fb02ae
python3-subscription-manager-rhsm-1.28.13-7.el8_4.x86_64.rpm SHA-256: e6b003bd6f7386ec4001b6cb8c6f34036f7a59288dc33ffb46d9d1bd397061a9
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 0785e091a654d5678ad9c5734593297dc341dc8c947b6d262c2ad4797a050b68
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 0785e091a654d5678ad9c5734593297dc341dc8c947b6d262c2ad4797a050b68
python3-syspurpose-1.28.13-7.el8_4.x86_64.rpm SHA-256: 6c691bc25ec2872fb3e0d2bf59b1483c2bde2b48e185d74295afbf5a082cc407
rhsm-gtk-1.28.13-7.el8_4.x86_64.rpm SHA-256: 5266416bcbd7f6cb315b4490ee6a03100dd854a14793659a4b1a3c39b7aa48db
rhsm-icons-1.28.13-7.el8_4.noarch.rpm SHA-256: e8cf83e8e33a78dfce3ae3a5566cfb5c922ca0c37240c4db35044cc8f2e0cd73
subscription-manager-1.28.13-7.el8_4.x86_64.rpm SHA-256: e3f886f265ebaec70ce14f5090305b4ce5bd231c394189cf350e5ab796e6a505
subscription-manager-cockpit-1.28.13-7.el8_4.noarch.rpm SHA-256: 478118b7830f579d20b52eae207ba1de7bac4f631ccfde1cea6259382d2d0de7
subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: a0866b84f4d29614a999ba62e039c6124c5db0cc0a8cca733677e78a1d8f0ecd
subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: a0866b84f4d29614a999ba62e039c6124c5db0cc0a8cca733677e78a1d8f0ecd
subscription-manager-debugsource-1.28.13-7.el8_4.x86_64.rpm SHA-256: 7c0d3894e14ea5e02235152eb52bc331187d7b44621a9bb0b349e52d44e8c1a6
subscription-manager-debugsource-1.28.13-7.el8_4.x86_64.rpm SHA-256: 7c0d3894e14ea5e02235152eb52bc331187d7b44621a9bb0b349e52d44e8c1a6
subscription-manager-initial-setup-addon-1.28.13-7.el8_4.x86_64.rpm SHA-256: 56cc96d15342c7d10158fefb18c6f28372e1fdad04a16f4c7e848c3688ef0e99
subscription-manager-migration-1.28.13-7.el8_4.x86_64.rpm SHA-256: 9f7c85cf6725796879ff7310b7dc0a49c8522d135180175826facfb185b97da4
subscription-manager-plugin-ostree-1.28.13-7.el8_4.x86_64.rpm SHA-256: e585b28ef33543a5c9c56d67e7218eae9a794cd51eec2229700ea34e6ee172c4
subscription-manager-rhsm-certificates-1.28.13-7.el8_4.x86_64.rpm SHA-256: 69eb9efb4dd1095da02072356164ad9d3088c1431d384340aba855830583213f

Red Hat Enterprise Linux Server - TUS 8.4

SRPM
subscription-manager-1.28.13-7.el8_4.src.rpm SHA-256: 04973de1a074fb1f5cf95e5e0bfa3d3d1220878f680003beb9040dbfacdc6f5d
x86_64
dnf-plugin-subscription-manager-1.28.13-7.el8_4.x86_64.rpm SHA-256: 5cde4beed5eb6437f3922a84332bf7155dcc8fa51966486632c9544c25814269
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 62893307c13f45e18c706dae675b43400b7385ac1ee2cf8c60158a5bd7fb02ae
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 62893307c13f45e18c706dae675b43400b7385ac1ee2cf8c60158a5bd7fb02ae
python3-subscription-manager-rhsm-1.28.13-7.el8_4.x86_64.rpm SHA-256: e6b003bd6f7386ec4001b6cb8c6f34036f7a59288dc33ffb46d9d1bd397061a9
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 0785e091a654d5678ad9c5734593297dc341dc8c947b6d262c2ad4797a050b68
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 0785e091a654d5678ad9c5734593297dc341dc8c947b6d262c2ad4797a050b68
python3-syspurpose-1.28.13-7.el8_4.x86_64.rpm SHA-256: 6c691bc25ec2872fb3e0d2bf59b1483c2bde2b48e185d74295afbf5a082cc407
rhsm-gtk-1.28.13-7.el8_4.x86_64.rpm SHA-256: 5266416bcbd7f6cb315b4490ee6a03100dd854a14793659a4b1a3c39b7aa48db
rhsm-icons-1.28.13-7.el8_4.noarch.rpm SHA-256: e8cf83e8e33a78dfce3ae3a5566cfb5c922ca0c37240c4db35044cc8f2e0cd73
subscription-manager-1.28.13-7.el8_4.x86_64.rpm SHA-256: e3f886f265ebaec70ce14f5090305b4ce5bd231c394189cf350e5ab796e6a505
subscription-manager-cockpit-1.28.13-7.el8_4.noarch.rpm SHA-256: 478118b7830f579d20b52eae207ba1de7bac4f631ccfde1cea6259382d2d0de7
subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: a0866b84f4d29614a999ba62e039c6124c5db0cc0a8cca733677e78a1d8f0ecd
subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: a0866b84f4d29614a999ba62e039c6124c5db0cc0a8cca733677e78a1d8f0ecd
subscription-manager-debugsource-1.28.13-7.el8_4.x86_64.rpm SHA-256: 7c0d3894e14ea5e02235152eb52bc331187d7b44621a9bb0b349e52d44e8c1a6
subscription-manager-debugsource-1.28.13-7.el8_4.x86_64.rpm SHA-256: 7c0d3894e14ea5e02235152eb52bc331187d7b44621a9bb0b349e52d44e8c1a6
subscription-manager-initial-setup-addon-1.28.13-7.el8_4.x86_64.rpm SHA-256: 56cc96d15342c7d10158fefb18c6f28372e1fdad04a16f4c7e848c3688ef0e99
subscription-manager-migration-1.28.13-7.el8_4.x86_64.rpm SHA-256: 9f7c85cf6725796879ff7310b7dc0a49c8522d135180175826facfb185b97da4
subscription-manager-plugin-ostree-1.28.13-7.el8_4.x86_64.rpm SHA-256: e585b28ef33543a5c9c56d67e7218eae9a794cd51eec2229700ea34e6ee172c4
subscription-manager-rhsm-certificates-1.28.13-7.el8_4.x86_64.rpm SHA-256: 69eb9efb4dd1095da02072356164ad9d3088c1431d384340aba855830583213f

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.4

SRPM
subscription-manager-1.28.13-7.el8_4.src.rpm SHA-256: 04973de1a074fb1f5cf95e5e0bfa3d3d1220878f680003beb9040dbfacdc6f5d
ppc64le
dnf-plugin-subscription-manager-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 9c25012645cc82531a311fba38e376b1a2b1dad1c93ce480d3580ef29b7bc1af
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.ppc64le.rpm SHA-256: dc08d9943a92ddaa3b4a98f100f80c5fa7b4e3a2045838828c97d4d6f4aa173a
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.ppc64le.rpm SHA-256: dc08d9943a92ddaa3b4a98f100f80c5fa7b4e3a2045838828c97d4d6f4aa173a
python3-subscription-manager-rhsm-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 304b9324997bd8c1dcf81e77c30a01bd18a82ed031440fecd5d0c40ad9c44803
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 7afaeadafca7611b313f2054cdb90023695697f766cae8b3d599773eaff443c9
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 7afaeadafca7611b313f2054cdb90023695697f766cae8b3d599773eaff443c9
python3-syspurpose-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 40c858a0f665f561de7841584fe87e91f1cde5b611461d684c5b6b80b57d3652
rhsm-gtk-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 733a0d2962ede7db0f5acd8c0649370c570f6766008687091ee3f4944ce91c37
rhsm-icons-1.28.13-7.el8_4.noarch.rpm SHA-256: e8cf83e8e33a78dfce3ae3a5566cfb5c922ca0c37240c4db35044cc8f2e0cd73
subscription-manager-1.28.13-7.el8_4.ppc64le.rpm SHA-256: e2955c3655f5d6f33e47b7a668d8d1c8d55aa33f975d999cd7f13f7ab7bacb95
subscription-manager-cockpit-1.28.13-7.el8_4.noarch.rpm SHA-256: 478118b7830f579d20b52eae207ba1de7bac4f631ccfde1cea6259382d2d0de7
subscription-manager-debuginfo-1.28.13-7.el8_4.ppc64le.rpm SHA-256: c034a2046505048cbe9e670df4664f074168326c7af19a6643b1759e4e584bc2
subscription-manager-debuginfo-1.28.13-7.el8_4.ppc64le.rpm SHA-256: c034a2046505048cbe9e670df4664f074168326c7af19a6643b1759e4e584bc2
subscription-manager-debugsource-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 5becb9821e014dae077bc3225e080dafbaf7ed066a417af652da7a0a05b169c8
subscription-manager-debugsource-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 5becb9821e014dae077bc3225e080dafbaf7ed066a417af652da7a0a05b169c8
subscription-manager-initial-setup-addon-1.28.13-7.el8_4.ppc64le.rpm SHA-256: a641f6d7a3d65601c2fb7b9a609c073eecb01e4c694387a5347aa5cb1d341de9
subscription-manager-migration-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 5a205b9971ac05354e1b8039c433a655f396c781c40b2cf3e08625226313d04f
subscription-manager-plugin-ostree-1.28.13-7.el8_4.ppc64le.rpm SHA-256: 4c6bbecbe7d0e9387bc1efe79a072b15a32a0fc6d5c75c0745eb9f39dcfe4884
subscription-manager-rhsm-certificates-1.28.13-7.el8_4.ppc64le.rpm SHA-256: a719a727515a34d1063e37a046b4a3faaabc96fd1355dbf57d3d32f2fc2a1496

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.4

SRPM
subscription-manager-1.28.13-7.el8_4.src.rpm SHA-256: 04973de1a074fb1f5cf95e5e0bfa3d3d1220878f680003beb9040dbfacdc6f5d
x86_64
dnf-plugin-subscription-manager-1.28.13-7.el8_4.x86_64.rpm SHA-256: 5cde4beed5eb6437f3922a84332bf7155dcc8fa51966486632c9544c25814269
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 62893307c13f45e18c706dae675b43400b7385ac1ee2cf8c60158a5bd7fb02ae
dnf-plugin-subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 62893307c13f45e18c706dae675b43400b7385ac1ee2cf8c60158a5bd7fb02ae
python3-subscription-manager-rhsm-1.28.13-7.el8_4.x86_64.rpm SHA-256: e6b003bd6f7386ec4001b6cb8c6f34036f7a59288dc33ffb46d9d1bd397061a9
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 0785e091a654d5678ad9c5734593297dc341dc8c947b6d262c2ad4797a050b68
python3-subscription-manager-rhsm-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: 0785e091a654d5678ad9c5734593297dc341dc8c947b6d262c2ad4797a050b68
python3-syspurpose-1.28.13-7.el8_4.x86_64.rpm SHA-256: 6c691bc25ec2872fb3e0d2bf59b1483c2bde2b48e185d74295afbf5a082cc407
rhsm-gtk-1.28.13-7.el8_4.x86_64.rpm SHA-256: 5266416bcbd7f6cb315b4490ee6a03100dd854a14793659a4b1a3c39b7aa48db
rhsm-icons-1.28.13-7.el8_4.noarch.rpm SHA-256: e8cf83e8e33a78dfce3ae3a5566cfb5c922ca0c37240c4db35044cc8f2e0cd73
subscription-manager-1.28.13-7.el8_4.x86_64.rpm SHA-256: e3f886f265ebaec70ce14f5090305b4ce5bd231c394189cf350e5ab796e6a505
subscription-manager-cockpit-1.28.13-7.el8_4.noarch.rpm SHA-256: 478118b7830f579d20b52eae207ba1de7bac4f631ccfde1cea6259382d2d0de7
subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: a0866b84f4d29614a999ba62e039c6124c5db0cc0a8cca733677e78a1d8f0ecd
subscription-manager-debuginfo-1.28.13-7.el8_4.x86_64.rpm SHA-256: a0866b84f4d29614a999ba62e039c6124c5db0cc0a8cca733677e78a1d8f0ecd
subscription-manager-debugsource-1.28.13-7.el8_4.x86_64.rpm SHA-256: 7c0d3894e14ea5e02235152eb52bc331187d7b44621a9bb0b349e52d44e8c1a6
subscription-manager-debugsource-1.28.13-7.el8_4.x86_64.rpm SHA-256: 7c0d3894e14ea5e02235152eb52bc331187d7b44621a9bb0b349e52d44e8c1a6
subscription-manager-initial-setup-addon-1.28.13-7.el8_4.x86_64.rpm SHA-256: 56cc96d15342c7d10158fefb18c6f28372e1fdad04a16f4c7e848c3688ef0e99
subscription-manager-migration-1.28.13-7.el8_4.x86_64.rpm SHA-256: 9f7c85cf6725796879ff7310b7dc0a49c8522d135180175826facfb185b97da4
subscription-manager-plugin-ostree-1.28.13-7.el8_4.x86_64.rpm SHA-256: e585b28ef33543a5c9c56d67e7218eae9a794cd51eec2229700ea34e6ee172c4
subscription-manager-rhsm-certificates-1.28.13-7.el8_4.x86_64.rpm SHA-256: 69eb9efb4dd1095da02072356164ad9d3088c1431d384340aba855830583213f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat X (formerly Twitter)

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility