CVE-2019-18904
Published: Apr 3, 2020
Modified: Sep 16, 2024
CVSS v3.1
6.5
Description
A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1 allows remote attackers to cause DoS against rmt by requesting migrations. This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise High Performance Computing 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Public Cloud 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Module for Server Applications 15 rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Server Applications 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Server 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.5.2-3.26.1. openSUSE Leap 15.1 rmt-server versions prior to 2.5.2-lp151.2.9.1.
| Vendor | Product | Versions |
|---|---|---|
SUSE | SUSE Linux Enterprise High Performance Computing 15-ESPOS | affected rmt-server - < 2.5.2-3.26.1 |
SUSE | SUSE Linux Enterprise High Performance Computing 15-LTSS | affected rmt-server - < 2.5.2-3.26.1 |
SUSE | SUSE Linux Enterprise Module for Public Cloud 15-SP1 | affected rmt-server - < 2.5.2-3.9.1 |
SUSE | SUSE Linux Enterprise Module for Server Applications 15 | affected rmt-server - < 2.5.2-3.26.1 |
SUSE | SUSE Linux Enterprise Module for Server Applications 15-SP1 | affected rmt-server - < 2.5.2-3.9.1 |
SUSE | SUSE Linux Enterprise Server 15-LTSS | affected rmt-server - < 2.5.2-3.26.1 |
SUSE | SUSE Linux Enterprise Server for SAP 15 | affected rmt-server - < 2.5.2-3.26.1 |
openSUSE | openSUSE Leap 15.1 | affected rmt-server - < 2.5.2-lp151.2.9.1 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now