Vulnerability Description
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Suse | Subscription Management Tool | < 3.0.37 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2018-12471?
CVE-2018-12471 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux...
How severe is CVE-2018-12471?
CVE-2018-12471 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12471?
Check the references section above for vendor advisories and patch information. Affected products include: Suse Subscription Management Tool.