CVE-2019-18904 PUBLISHED CVSS 6.5 MEDIUM

A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1 allows remote attackers to cause DoS against rmt by requesting migrations. This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise High Performance Computing 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Public Cloud 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Module for Server Applications 15 rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Server Applications 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Server 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.5.2-3.26.1. openSUSE Leap 15.1 rmt-server versions prior to 2.5.2-lp151.2.9.1.

EPSS 0.93% · 76.0th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.93%
76.0th percentile

Affected Products

VendorProductVersions
SUSESUSE Linux Enterprise Server for SAP 15rmt-server
SUSESUSE Linux Enterprise Module for Server Applications 15-SP1rmt-server
SUSESUSE Linux Enterprise High Performance Computing 15-ESPOSrmt-server
opensusermt-server0, 0, 0
SUSESUSE Linux Enterprise Module for Public Cloud 15-SP1rmt-server
SUSESUSE Linux Enterprise High Performance Computing 15-LTSSrmt-server
openSUSEopenSUSE Leap 15.1rmt-server
SUSESUSE Linux Enterprise Module for Server Applications 15rmt-server
SUSESUSE Linux Enterprise Server 15-LTSSrmt-server

Timeline

References

Open in Interactive Console →