First published: Thu Oct 04 2018(Updated: )
A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Subscription Management Tool | <3.0.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12470 has a moderate severity level due to the risk of arbitrary SQL execution.
To fix CVE-2018-12470, upgrade to SUSE Linux SMT version 3.0.37 or later.
CVE-2018-12470 is caused by a SQL Injection vulnerability in the RegistrationSharing module of SUSE Linux SMT.
CVE-2018-12470 affects users of SUSE Linux SMT versions prior to 3.0.37.
Yes, CVE-2018-12470 can be exploited remotely by attackers to execute arbitrary SQL statements.