CVE-2018-12472: Suse Subscription Management Tool
Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
Affected products
- Suse Subscription Management Tool: before 3.0.37 (fixed in 3.0.37)
Published 2018-10-04. Last modified 2026-06-17.