← Back

Subscription Management Tool

subscription_management_tool

Vendor: Suse • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
8.1 HIGH· v3
6.4 MEDIUM· v2
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior...Show more
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing blocking elements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.Show less
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.