CVE-2018-12470: Suse Subscription Management Tool

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.

Affected products

  • Suse Subscription Management Tool: before 3.0.37 (fixed in 3.0.37)

Published 2018-10-04. Last modified 2026-06-17.