# SLES11-SP3 Package update

**URL:** <https://forums.suse.com/t/sles11-sp3-package-update/26684>\
**Category:** SLES Updates\
**Created:** [February 12, 2015, 3:35pm UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684 "2015-02-12T15:35:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vinishrustagi](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@vinishrustagi](https://forums.suse.com/u/vinishrustagi)\
**Post date:** [February 12, 2015, 3:35pm UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684/1 "2015-02-12T15:35:46Z")

</div>

Hi Team,

I have installed OES11-SP2-addon\_with\_SLES11-SP3-x86\_64. Now i just scanned this server by using Nessus Tool.  
It showing a lot of vulnerabilities.  
please suggest me how to fix this?

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [February 12, 2015, 4:10pm UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684/2 "2015-02-12T16:10:08Z")

</div>

It would help if you expounded, in great detail, about the  
“vulnerabilities” found, and preferably included code to test the exploits.

Often security scanning tools err far on the side of caution, reporting  
many things which may be problems based on nothing more than a detected  
version number (a terrible test). As a result, details are needed, as are  
proper tests.

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [February 12, 2015, 5:16pm UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684/3 "2015-02-12T17:16:54Z")

</div>

On 12/02/2015 13:44, vinishrustagi wrote:  
[color=blue]

> I have installed OES11-SP2-addon\_with\_SLES11-SP3-x86\_64. Now i just  
> scanned this server by using Nessus Tool.  
> It showing a lot of vulnerabilities.  
> please suggest me how to fix this?[/color]

After installing OES11 SP2 with SLES11 SP3 did you then register the  
server against the Novell Customer Center (or your own SMT server) and  
fully patch the server?

As ab notes, often vulnerabilities are mis-reported because the scanning  
software blindly checks the version numbers without actually checking  
the vulnerability. For stability reasons, SUSE backport a lot of  
security fixes from later versions to earlier versions so whilst at  
first glance a component may seem vulnerable it’s actually not.

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.

---

<div class="post-metadata">

**Author:** ![vinishrustagi](https://avatars.discourse-cdn.com/v4/letter/v/13edae/32.png) [@vinishrustagi](https://forums.suse.com/u/vinishrustagi)\
**Post date:** [February 13, 2015, 12:10pm UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684/4 "2015-02-13T12:10:55Z")

</div>

Is SuSE subscription required to update the patches?  
Till now, we don’t have any paid subscription for SLES11, but we have license of Novell Groupwise.  
Is Suse server also included in that.Please suggest.

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [February 13, 2015, 1:20pm UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684/5 "2015-02-13T13:20:20Z")

</div>

On 02/13/2015 03:14 AM, vinishrustagi wrote:[color=blue]

> Is SuSE subscription required to update the patches?[/color]

Via software repositories? Yes.  
[color=blue]

> Till now, we don’t have any paid subscription for SLES11, but we have  
> license of Novell Groupwise.  
> Is Suse server also included in that.Please suggest.[/color]

Whether or not it comes with SLES licenses is beyond me; your GW sales or  
account representative should be able to tell you easily.

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [February 13, 2015, 1:25pm UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684/6 "2015-02-13T13:25:06Z")

</div>

On 13/02/2015 10:14, vinishrustagi wrote:  
[color=blue]

> Is SuSE subscription required to update the patches?[/color]

Yes.  
[color=blue]

> Till now, we don’t have any paid subscription for SLES11, but we have  
> license of Novell Groupwise.  
> Is Suse server also included in that.Please suggest.[/color]

I think that a license for SLES is included with GroupWise however you  
installed Novell Open Enterprise Server (OES) which won’t be covered. If  
you have OES you need a subscription from Novell which will cover  
updates for both OES and the underlying SLES - you need to update both.

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/5/5012ba89e3ffb5220dac47d5ea0ba032e2fe1cb6.png) [@system](https://forums.suse.com/u/system)\
**Post date:** [December 21, 2016, 1:21am UTC](https://forums.suse.com/t/sles11-sp3-package-update/26684/7 "2016-12-21T01:21:07Z")

</div>

Am 13.02.2015 um 12:25 schrieb Simon Flood:[color=blue]

> On 13/02/2015 10:14, vinishrustagi wrote:  
> [color=green]
> 
> > Is SuSE subscription required to update the patches?[/color]
> 
> Yes.  
> [color=green]
> 
> > Till now, we don’t have any paid subscription for SLES11, but we have  
> > license of Novell Groupwise.  
> > Is Suse server also included in that.Please suggest.[/color]
> 
> I think that a license for SLES is included with GroupWise however you  
> installed Novell Open Enterprise Server (OES) which won’t be covered. If  
> you have OES you need a subscription from Novell which will cover  
> updates for both OES and the underlying SLES - you need to update both.[/color]

Not to mention that while SLES is Open Source and you are legally  
allowed to run it without paying (albeit have no support and no access  
to patches), OES is not. Using OES without valid license is software piracy.

## CU,

Massimo Rosen  
Micro Focus Knowledge Partner  
No emails please!  
[http://www.cfc-it.de](http://www.cfc-it.de)
