First published: Thu Sep 27 2018(Updated: )
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Suse Subscription Management Tool | <3.0.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12472 is classified with a medium severity rating due to improper authentication vulnerabilities.
To fix CVE-2018-12472, upgrade your SUSE Linux SMT to version 3.0.37 or later.
CVE-2018-12472 allows remote attackers to spoof a sibling server, potentially causing unauthorized access.
CVE-2018-12472 affects all versions of SUSE Linux SMT prior to 3.0.37.
Yes, CVE-2018-12472 can be exploited by remote attackers through manipulation of the HOST header.