A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
The product implements an authentication technique, but it skips a step that weakens the technique.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.