Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2017-7513
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.
0
Attacker Value
Unknown
CVE-2014-3595
Disclosure Date: September 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.
0
Attacker Value
Unknown
CVE-2012-0059
Disclosure Date: February 05, 2014 (last updated October 05, 2023)
Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5.4 includes cleartext user passwords in an error message when a system registration XML-RPC call fails, which allows remote administrators to obtain the password by reading (1) the server log and (2) an email.
0
Attacker Value
Unknown
CVE-2013-4480
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
0
Attacker Value
Unknown
CVE-2013-2056
Disclosure Date: July 31, 2013 (last updated October 05, 2023)
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.
0
Attacker Value
Unknown
CVE-2012-1145
Disclosure Date: June 16, 2012 (last updated October 04, 2023)
spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads.
0
Attacker Value
Unknown
CVE-2011-4346
Disclosure Date: December 10, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the web interface in Red Hat Network (RHN) Satellite 5.4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field of the asset tag in a Custom Info page.
0
Attacker Value
Unknown
CVE-2011-3544
Disclosure Date: October 19, 2011 (last updated July 25, 2024)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.
0
Attacker Value
Unknown
CVE-2009-4139
Disclosure Date: July 27, 2011 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Spacewalk Java site packages (aka spacewalk-java) 1.2.39 in Spacewalk, as used in the server in Red Hat Network Satellite 5.3.0 through 5.4.1 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that (1) disable the current user account, (2) add user accounts, or (3) modify user accounts to have administrator privileges.
0
Attacker Value
Unknown
CVE-2010-1171
Disclosure Date: April 18, 2011 (last updated October 04, 2023)
Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.
0