CVE-2018-12471

A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
susesubscription_management_tool
𝑥
< 3.0.37
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
perl-File-Touch
suse enterprise sap 12
0.11-3.2.2
fixed
suse enterprise sap 12 SP3
0.11-3.2.2
fixed
suse enterprise sap 12 SP4
0.11-3.2.2
fixed
suse enterprise sap 12 SP5
0.11-3.2.2
fixed
suse enterprise server 12
0.11-3.2.2
fixed
suse enterprise server 12 SP3
0.11-3.2.2
fixed
suse enterprise server 12 SP4
0.11-3.2.2
fixed
suse enterprise server 12 SP5
0.11-3.2.2
fixed
res-signingkeys
suse enterprise sap 12 SP3
3.0.37-52.23.6
fixed
suse enterprise sap 12 SP5
3.0.42-52.38.1
fixed
suse enterprise server 12 SP1
3.0.37-52.23.6
fixed
suse enterprise server 12 SP2
3.0.37-52.23.6
fixed
suse enterprise server 12 SP3
3.0.37-52.23.6
fixed
suse enterprise server 12 SP5
3.0.42-52.38.1
fixed
smt
suse enterprise sap 12 SP3
3.0.37-52.23.6
fixed
suse enterprise sap 12 SP5
3.0.42-52.38.1
fixed
suse enterprise server 12 SP1
3.0.37-52.23.6
fixed
suse enterprise server 12 SP2
3.0.37-52.23.6
fixed
suse enterprise server 12 SP3
3.0.37-52.23.6
fixed
suse enterprise server 12 SP5
3.0.42-52.38.1
fixed
smt-ha
suse enterprise sap 12
3.0.37-52.23.6
fixed
suse enterprise sap 12 SP3
3.0.37-52.23.6
fixed
suse enterprise sap 12 SP4
3.0.37-52.23.6
fixed
suse enterprise sap 12 SP5
3.0.37-52.23.6
fixed
suse enterprise server 12
3.0.37-52.23.6
fixed
suse enterprise server 12 SP3
3.0.37-52.23.6
fixed
suse enterprise server 12 SP4
3.0.37-52.23.6
fixed
suse enterprise server 12 SP5
3.0.37-52.23.6
fixed
smt-support
suse enterprise sap 12 SP3
3.0.37-52.23.6
fixed
suse enterprise sap 12 SP5
3.0.42-52.38.1
fixed
suse enterprise server 12 SP1
3.0.37-52.23.6
fixed
suse enterprise server 12 SP2
3.0.37-52.23.6
fixed
suse enterprise server 12 SP3
3.0.37-52.23.6
fixed
suse enterprise server 12 SP5
3.0.42-52.38.1
fixed
yast2-smt
suse enterprise server 12 SP1
3.0.14-10.6.2
fixed