CVE-2018-12472

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
04/10/2018
Last modified:
07/11/2023

Description

A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:suse:subscription_management_tool:*:*:*:*:*:*:*:* 3.0.37 (excluding)


References to Advisories, Solutions, and Tools