CVE-2019-18906

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/06/2021
Last modified:
14/04/2023

Description

A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opensuse:cryptctl:*:*:*:*:*:*:*:* 2.4 (excluding)
cpe:2.3:o:suse:linux_enterprise_server:12:sp5:*:*:*:sap:*:*
cpe:2.3:a:opensuse:cryptctl:*:*:*:*:*:*:*:* 2.4 (excluding)
cpe:2.3:a:suse:manager_server:4.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools