<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1"
><DocumentTitle xml:lang="en"
>Recommended update for apache-commons-io</DocumentTitle
><DocumentType
>SUSE Patch</DocumentType
><DocumentPublisher Type="Vendor"
><ContactDetails
>security@suse.de</ContactDetails
><IssuingAuthority
>SUSE Security Team</IssuingAuthority
></DocumentPublisher
><DocumentTracking
><Identification
><ID
>SUSE-RU-2025:1150-1</ID
></Identification
><Status
>Final</Status
><Version
>1</Version
><RevisionHistory
><Revision
><Number
>1</Number
><Date
>2025-04-07T07:47:08Z</Date
><Description
>current</Description
></Revision
></RevisionHistory
><InitialReleaseDate
>2025-04-07T07:47:08Z</InitialReleaseDate
><CurrentReleaseDate
>2025-04-07T07:47:08Z</CurrentReleaseDate
><Generator
><Engine
>cve-database/bin/generate-cvrf.pl</Engine
><Date
>2017-02-24T01:00:00Z</Date
></Generator
></DocumentTracking
><DocumentNotes
><Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en"
>Recommended update for apache-commons-io</Note
><Note Title="Details" Type="General" Ordinal="2" xml:lang="en"
>This update for apache-commons-io fixes the following issues:

apache-commons-io was updated from version 2.15.1 to 2.18.0:
    
- Key changes across versions:
  * Cleaner code and updated dependencies
  * Improved security when handling serialized data with the new safe deserialization feature
  * New features for advanced file and stream operations
  * Various bugs were fixed to improve reliability with fewer crashes and unexpected errors
  * For the full list of changes please consult the packaged RELEASE-NOTES.txt
    
- Already fixed in previous version:
  * CVE-2024-47554: Untrusted input to XmlStreamReader can lead to uncontrolled resource consumption (bsc#1231298)
</Note
><Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en"
>The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note
><Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en"
>Container bci/openjdk-devel:17-2025-1150,Container bci/openjdk-devel:latest-2025-1150,Container suse/manager/5.0/x86_64/server:latest-2025-1150,Container suse/multi-linux-manager/5.1/x86_64/server:latest-2025-1150,Image SLES15-SP4-Manager-Server-4-3-BYOS-2025-1150,Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure-2025-1150,Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2-2025-1150,Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE-2025-1150,Image server-image-2025-1150,SUSE-2025-1150,SUSE-SLE-Module-Basesystem-15-SP6-2025-1150,SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-1150,SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1150,SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1150,SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1150,SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1150,SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-1150,SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1150,SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1150,SUSE-SLE-Product-SLES_SAP-15-SP3-2025-1150,SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1150,SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1150,SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-1150,SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-1150,SUSE-Storage-7.1-2025-1150,openSUSE-SLE-15.6-2025-1150</Note
></DocumentNotes
><DocumentDistribution xml:lang="en"
>Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution
><DocumentReferences
><Reference Type="Self"
><URL
>https://www.suse.com/support/update/announcement/-2025-1150/suse-ru-20251150-1/</URL
><Description
>Link for SUSE-RU-2025:1150-1</Description
></Reference
><Reference Type="Self"
><URL
>https://lists.suse.com/pipermail/sle-updates/2025-April/038917.html</URL
><Description
>E-Mail link for SUSE-RU-2025:1150-1</Description
></Reference
><Reference Type="Self"
><URL
>https://www.suse.com/support/security/rating/</URL
><Description
>SUSE Security Ratings</Description
></Reference
><Reference Type="Self"
><URL
>https://bugzilla.suse.com/1231298</URL
><Description
>SUSE Bug 1231298</Description
></Reference
><Reference Type="Self"
><URL
>https://www.suse.com/security/cve/CVE-2024-47554/</URL
><Description
>SUSE CVE CVE-2024-47554 page</Description
></Reference
></DocumentReferences
><ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1"
><Branch Type="Product Family" Name="Container bci/openjdk-devel:17"
><Branch Type="Product Name" Name="Container bci/openjdk-devel:17"
><FullProductName ProductID="Container bci/openjdk-devel:17"
>Container bci/openjdk-devel:17</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Container bci/openjdk-devel:latest"
><Branch Type="Product Name" Name="Container bci/openjdk-devel:latest"
><FullProductName ProductID="Container bci/openjdk-devel:latest"
>Container bci/openjdk-devel:latest</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Container suse/manager/5.0/x86_64/server:latest"
><Branch Type="Product Name" Name="Container suse/manager/5.0/x86_64/server:latest"
><FullProductName ProductID="Container suse/manager/5.0/x86_64/server:latest"
>Container suse/manager/5.0/x86_64/server:latest</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Container suse/multi-linux-manager/5.1/x86_64/server:latest"
><Branch Type="Product Name" Name="Container suse/multi-linux-manager/5.1/x86_64/server:latest"
><FullProductName ProductID="Container suse/multi-linux-manager/5.1/x86_64/server:latest"
>Container suse/multi-linux-manager/5.1/x86_64/server:latest</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS"
><Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS"
>Image SLES15-SP4-Manager-Server-4-3-BYOS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure"
><Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure"
>Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2"
><Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2"
>Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE"
><Branch Type="Product Name" Name="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE"
>Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="Image server-image"
><Branch Type="Product Name" Name="Image server-image"
><FullProductName ProductID="Image server-image"
>Image server-image</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Enterprise Storage 7.1"
><Branch Type="Product Name" Name="SUSE Enterprise Storage 7.1"
><FullProductName ProductID="SUSE Enterprise Storage 7.1" CPE="cpe:/o:suse:ses:7.1"
>SUSE Enterprise Storage 7.1</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp3"
>SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp4"
>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp4"
>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS" CPE="cpe:/o:suse:sle_hpc-espos:15:sp5"
>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp5"
>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Basesystem 15 SP6"
><Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP6"
><FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6" CPE="cpe:/o:suse:sle-module-basesystem:15:sp6"
>SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP3-LTSS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP3-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise Server 15 SP3-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp3"
>SUSE Linux Enterprise Server 15 SP3-LTSS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP4-LTSS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP4-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise Server 15 SP4-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp4"
>SUSE Linux Enterprise Server 15 SP4-LTSS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP5-LTSS"
><Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP5-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise Server 15 SP5-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp5"
>SUSE Linux Enterprise Server 15 SP5-LTSS</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP3"
><Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP3"
><FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP3" CPE="cpe:/o:suse:sles_sap:15:sp3"
>SUSE Linux Enterprise Server for SAP Applications 15 SP3</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP4"
><Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP4"
><FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP4" CPE="cpe:/o:suse:sles_sap:15:sp4"
>SUSE Linux Enterprise Server for SAP Applications 15 SP4</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP5"
><Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP5"
><FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP5" CPE="cpe:/o:suse:sles_sap:15:sp5"
>SUSE Linux Enterprise Server for SAP Applications 15 SP5</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Manager Proxy 4.3"
><Branch Type="Product Name" Name="SUSE Manager Proxy 4.3"
><FullProductName ProductID="SUSE Manager Proxy 4.3" CPE="cpe:/o:suse:suse-manager-proxy:4.3"
>SUSE Manager Proxy 4.3</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="SUSE Manager Server 4.3"
><Branch Type="Product Name" Name="SUSE Manager Server 4.3"
><FullProductName ProductID="SUSE Manager Server 4.3" CPE="cpe:/o:suse:suse-manager-server:4.3"
>SUSE Manager Server 4.3</FullProductName
></Branch
></Branch
><Branch Type="Product Family" Name="openSUSE Leap 15.6"
><Branch Type="Product Name" Name="openSUSE Leap 15.6"
><FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6"
>openSUSE Leap 15.6</FullProductName
></Branch
></Branch
><Branch Type="Product Version" Name="apache-commons-io-2.18.0-150200.3.15.1"
><FullProductName ProductID="apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1</FullProductName
></Branch
><Branch Type="Product Version" Name="apache-commons-io-javadoc-2.18.0-150200.3.15.1"
><FullProductName ProductID="apache-commons-io-javadoc-2.18.0-150200.3.15.1"
>apache-commons-io-javadoc-2.18.0-150200.3.15.1</FullProductName
></Branch
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Container bci/openjdk-devel:17"
><FullProductName ProductID="Container bci/openjdk-devel:17:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Container bci/openjdk-devel:17</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Container bci/openjdk-devel:latest"
><FullProductName ProductID="Container bci/openjdk-devel:latest:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Container bci/openjdk-devel:latest</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/manager/5.0/x86_64/server:latest"
><FullProductName ProductID="Container suse/manager/5.0/x86_64/server:latest:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Container suse/manager/5.0/x86_64/server:latest</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Container suse/multi-linux-manager/5.1/x86_64/server:latest"
><FullProductName ProductID="Container suse/multi-linux-manager/5.1/x86_64/server:latest:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Container suse/multi-linux-manager/5.1/x86_64/server:latest</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE"
><FullProductName ProductID="Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="Image server-image"
><FullProductName ProductID="Image server-image:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of Image server-image</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 7.1"
><FullProductName ProductID="SUSE Enterprise Storage 7.1:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Enterprise Storage 7.1</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP6"
><FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP6:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP6</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP3-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise Server 15 SP3-LTSS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise Server 15 SP3-LTSS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP4-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise Server 15 SP4-LTSS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise Server 15 SP4-LTSS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP5-LTSS"
><FullProductName ProductID="SUSE Linux Enterprise Server 15 SP5-LTSS:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise Server 15 SP5-LTSS</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP3"
><FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP3:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP3</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP4"
><FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP4:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP4</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP5"
><FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP5:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP5</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 4.3"
><FullProductName ProductID="SUSE Manager Proxy 4.3:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Manager Proxy 4.3</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 4.3"
><FullProductName ProductID="SUSE Manager Server 4.3:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of SUSE Manager Server 4.3</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6"
><FullProductName ProductID="openSUSE Leap 15.6:apache-commons-io-2.18.0-150200.3.15.1"
>apache-commons-io-2.18.0-150200.3.15.1 as a component of openSUSE Leap 15.6</FullProductName
></Relationship
><Relationship ProductReference="apache-commons-io-javadoc-2.18.0-150200.3.15.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6"
><FullProductName ProductID="openSUSE Leap 15.6:apache-commons-io-javadoc-2.18.0-150200.3.15.1"
>apache-commons-io-javadoc-2.18.0-150200.3.15.1 as a component of openSUSE Leap 15.6</FullProductName
></Relationship
></ProductTree
><Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1"
><Notes
><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en"
>Uncontrolled Resource Consumption vulnerability in Apache Commons IO.

The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.


This issue affects Apache Commons IO: from 2.0 before 2.14.0.

Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.</Note
></Notes
><CVE
>CVE-2024-47554</CVE
><ProductStatuses
><Status Type="Fixed"
><ProductID
>Container bci/openjdk-devel:17:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Container bci/openjdk-devel:latest:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Container suse/manager/5.0/x86_64/server:latest:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Container suse/multi-linux-manager/5.1/x86_64/server:latest:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Image SLES15-SP4-Manager-Server-4-3-BYOS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>Image server-image:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Enterprise Storage 7.1:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise Module for Basesystem 15 SP6:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise Server 15 SP3-LTSS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise Server 15 SP4-LTSS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise Server 15 SP5-LTSS:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise Server for SAP Applications 15 SP3:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise Server for SAP Applications 15 SP4:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Linux Enterprise Server for SAP Applications 15 SP5:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Manager Proxy 4.3:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>SUSE Manager Server 4.3:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>openSUSE Leap 15.6:apache-commons-io-2.18.0-150200.3.15.1</ProductID
><ProductID
>openSUSE Leap 15.6:apache-commons-io-javadoc-2.18.0-150200.3.15.1</ProductID
></Status
></ProductStatuses
><Threats
><Threat Type="Impact"
><Description
>moderate</Description
></Threat
></Threats
><Remediations
><Remediation Type="Vendor Fix"
><Description xml:lang="en"
>To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description
><URL
>https://www.suse.com/support/update/announcement/-2025-1150/suse-ru-20251150-1/</URL
></Remediation
></Remediations
><References
><Reference
><URL
>https://www.suse.com/security/cve/CVE-2024-47554.html</URL
><Description
>CVE-2024-47554</Description
></Reference
><Reference
><URL
>https://bugzilla.suse.com/1231298</URL
><Description
>SUSE Bug 1231298</Description
></Reference
></References
></Vulnerability
></cvrfdoc
>
