CVE-2018-12471

A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
Configurations

Configuration 1 (hide)

cpe:2.3:a:suse:subscription_management_tool:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:45

Type Values Removed Values Added
References () https://bugzilla.suse.com/show_bug.cgi?id=1103809 - () https://bugzilla.suse.com/show_bug.cgi?id=1103809 -
CVSS v2 : 6.4
v3 : 8.1
v2 : 6.4
v3 : 6.5

07 Nov 2023, 02:52

Type Values Removed Values Added
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1103809 - Issue Tracking, Third Party Advisory () https://bugzilla.suse.com/show_bug.cgi?id=1103809 -

Information

Published : 2018-10-04 14:29

Updated : 2024-11-21 03:45


NVD link : CVE-2018-12471

Mitre link : CVE-2018-12471

CVE.ORG link : CVE-2018-12471


JSON object : View

Products Affected

suse

  • subscription_management_tool
CWE
CWE-611

Improper Restriction of XML External Entity Reference