CVE-2018-12472: Suse Subscription Management Tool

Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.

A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.

Affected products

  • Suse Subscription Management Tool: before 3.0.37 (fixed in 3.0.37)

Published 2018-10-04. Last modified 2026-06-17.