A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
References
Link | Resource |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1103809 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2018-10-04 07:29
Updated : 2019-10-09 16:33
NVD link : CVE-2018-12471
Mitre link : CVE-2018-12471
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
suse
- subscription_management_tool