CVE-2018-19638
Last modified
CVE-2018-19638 is a low-severity vulnerability rated 2.2/10 on the CVSS scale. In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
Metrics
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opensuse | Supportutils | < 3.1-5.7.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-19638?
How severe is CVE-2018-19638?
How do I fix CVE-2018-19638?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-19629A Denial of Service vulnerability in the ImageNow Server ser…
- CVE-2018-19630cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and …
- CVE-2018-19634CA Service Desk Manager 14.1 and 17 contain a vulnerability …7.5
- CVE-2018-19635CA Service Desk Manager 14.1 and 17 contain a vulnerability …
- CVE-2018-19636Supportutils, before version 3.1-5.7.1, when run with comman…7.3
- CVE-2018-19637Supportutils, before version 3.1-5.7.1, wrote data to static…2.8
- CVE-2018-19639If supportutils before version 3.1-5.7.1 is run with -v to p…6.7
- CVE-2018-19640If the attacker manages to create files in the directory use…4.4
- CVE-2018-19641Unauthenticated remote code execution issue in Micro Focus S…6.1
- CVE-2018-19642Denial of service issue in Micro Focus Solutions Business Ma…5.1
- CVE-2018-19643Information leakage issue in Micro Focus Solutions Business …4.7
- CVE-2018-19644Reflected cross site script issue in Micro Focus Solutions B…5
Are you affected by CVE-2018-19638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
