First published: Wed Jun 30 2021(Updated: )
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This issue affects: SUSE Linux Enterprise Server for SAP 12-SP5 cryptctl versions prior to 2.4. SUSE Manager Server 4.0 cryptctl versions prior to 2.4.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Cryptctl | <2.4 | |
Suse Linux Enterprise Server Sap | =12-sp5 | |
SUSE Manager Server | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18906 is an Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5 and SUSE Manager Server 4.0.
CVE-2019-18906 has a severity rating of 9.8 (Critical).
CVE-2019-18906 affects cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5 (up to version 2.4) and SUSE Manager Server 4.0.
CVE-2019-18906 affects Opensuse Cryptctl versions up to 2.4.
No, Suse Linux Enterprise Server 12-SP5 is not vulnerable to CVE-2019-18906.