← Vulnerability feed

Vulnerability record · CVE-2019-18900 · published 24 January 2020

CVE-2019-18900: Opensuse libzypp incorrect default permissions vulnerability

Opensuse · Libzypp

: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.

3.3 CVSS 3.1 Low EPSS 0.30% · top 79.6% CWE-276 · Incorrect default permissions
3.3CVSS 3.1 base score, v2 2.1
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-18900 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-9269Opensuse libzypp improper input validation vulnerabilityIn libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down…EPSS 2.2%8.8CVE-2026-44941Opensuse libzypp relative path traversal vulnerabilityA relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a maliciou…EPSS 0.53%8.8CVE-2026-25707Opensuse libzypp relative path traversal vulnerabilityA relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repo…EPSS 0.60%8.1CVE-2017-7435Opensuse libzypp improper input validation vulnerabilityIn libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malic…EPSS 1.8%8.1CVE-2017-7436Opensuse libzypp improper input validation vulnerabilityIn libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malic…EPSS 1.8%7.8CVE-2018-7685Opensuse libzypp improper verification of cryptographic signature vulnerabilityThe decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call woul…EPSS 0.29%7.8CVE-2026-87886Acronis Backup plugins for cPanel, Plesk and DirectAdmin local privilege escalationAcronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escal…KEVEPSS 0.23%analysed6.5CVE-2022-22948VMware vCenter Server information disclosure via incorrect file permissionsvCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because …KEVEPSS 13%analysed

Source: NIST National Vulnerability Database (record CVE-2019-18900), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.