CVE-2018-12471: External Entity processing in the RegistrationSharing module
Published Oct 4, 2018
·Updated
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
Affected Software
1 affected component
SUSE Subscription Management Tool<3.0.37
Event History
Oct 4, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-12471?
CVE-2018-12471 has been classified with a medium severity level due to its potential to disclose sensitive information.
2
How do I fix CVE-2018-12471?
To mitigate CVE-2018-12471, upgrade to SUSE Linux SMT version 3.0.37 or later.
3
What kind of attacks can exploit CVE-2018-12471?
CVE-2018-12471 can be exploited by remote attackers to read sensitive data or cause a denial of service.
4
Which versions of SUSE Linux SMT are affected by CVE-2018-12471?
CVE-2018-12471 affects SUSE Linux SMT versions prior to 3.0.37.
5
What is an External Entity Reference (XXE) vulnerability?
An External Entity Reference (XXE) vulnerability allows attackers to interfere with the processing of XML data.