CVE-2018-12472: Authentication bypass in sibling check
Published Oct 4, 2018
·Updated
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
Affected Software
1 affected component
SUSE Subscription Management Tool<3.0.37
Event History
Oct 4, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-12472?
CVE-2018-12472 is classified with a medium severity rating due to improper authentication vulnerabilities.
2
How do I fix CVE-2018-12472?
To fix CVE-2018-12472, upgrade your SUSE Linux SMT to version 3.0.37 or later.
3
What impact does CVE-2018-12472 have on my system?
CVE-2018-12472 allows remote attackers to spoof a sibling server, potentially causing unauthorized access.
4
Which versions are affected by CVE-2018-12472?
CVE-2018-12472 affects all versions of SUSE Linux SMT prior to 3.0.37.
5
Is CVE-2018-12472 easily exploitable?
Yes, CVE-2018-12472 can be exploited by remote attackers through manipulation of the HOST header.