CVE-2019-18904
A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1 allows remote attackers to cause DoS against rmt by requesting migrations. This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise High Performance Computing 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Public Cloud 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Module for Server Applications 15 rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Server Applications 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Server 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.5.2-3.26.1. openSUSE Leap 15.1 rmt-server versions prior to 2.5.2-lp151.2.9.1.
- Affected products
- Suse Linux Enterprise High Performance Computing 15-Espos, Suse Linux Enterprise High Performance Computing 15-Ltss, Suse Linux Enterprise Module For Public Cloud 15-Sp1, Suse Linux Enterprise Module For Server Applications 15, Suse Linux Enterprise Module For Server Applications 15-Sp1, Suse Linux Enterprise Server 15, Suse Linux Enterprise Server For Sap 15, Suse
- Opensuse Rmt-server
- ≤ 2.5.2-3.26.1
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.5% (73th percentile)
- Weakness
- CWE-400
- NVD status
- Modified
- Published
- 2020-04-03
No indexed exploits for CVE-2019-18904 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-18904 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.