CVE-2009-0788
published 2011-04-18CVE-2009-0788: Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.71%
74.7th percentile
Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_satellite_server | — | — |
| redhat | network_satellite_server | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
vendor_redhat·2011-04-11·CVSS 6.4
CVE-2009-0788 [MEDIUM] rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.
GHSA
GHSA-688x-7w25-gh2x: Red Hat Network (RHN) Satellite Server 5
ghsa_unreviewed·2022-05-02
CVE-2009-0788 [MEDIUM] CWE-200 GHSA-688x-7w25-gh2x: Red Hat Network (RHN) Satellite Server 5
Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1171 CVE-2009-0788 spacewalk-backend various flaws [fedora-all]
bugzilla·2011-04-11·CVSS 6.4
CVE-2010-1171 [MEDIUM] CVE-2010-1171 CVE-2009-0788 spacewalk-backend various flaws [fedora-all]
CVE-2010-1171 CVE-2009-0788 spacewalk-backend various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=584118
Please note: this issue affects multiple s
Bugzilla
CVE-2009-0788 rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
bugzilla·2009-03-20·CVSS 6.4
CVE-2009-0788 [MEDIUM] CVE-2009-0788 rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
CVE-2009-0788 rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
A flaw was found in the way RHN Satellite rewrote certain URLs.
An unauthenticated user could use a specially-crafted HTTP
request to obtain sensitive information about the host system
RHN Satellite was running on. They could also use RHN Satellite
as a distributed denial of service tool, forcing it to connect
to an arbitrary service at an arbitrary IP address via a
specially-crafted HTTP request.
Discussion:
The preliminary embargo date for this issue has been set up to
Monday, 9-th of May, 2011.
---
(In reply to comment #25)
The preliminary embargo date for this issue has been moved to
earlier date, Monday, 11-th of April, 2011.
---
This issue has been addressed in foll
http://secunia.com/advisories/44150http://www.redhat.com/support/errata/RHSA-2011-0434.htmlhttp://www.securityfocus.com/bid/47316http://www.securitytracker.com/id?1025316http://www.vupen.com/english/advisories/2011/0967https://bugzilla.redhat.com/show_bug.cgi?id=491365https://exchange.xforce.ibmcloud.com/vulnerabilities/66691http://secunia.com/advisories/44150http://www.redhat.com/support/errata/RHSA-2011-0434.htmlhttp://www.securityfocus.com/bid/47316http://www.securitytracker.com/id?1025316http://www.vupen.com/english/advisories/2011/0967https://bugzilla.redhat.com/show_bug.cgi?id=491365https://exchange.xforce.ibmcloud.com/vulnerabilities/66691
2011-04-18
Published