CVE-2010-2236
published 2014-04-15CVE-2010-2236: The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy…
PriorityP338medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
3.06%
86.1th percentile
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_proxy | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| redhat | spacewalk-java | <= 2.1.147-1 | — |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4343-3cxx-2jqg: The monitoring probe display in spacewalk-java before 2
ghsa_unreviewed·2022-05-13
CVE-2010-2236 [MEDIUM] CWE-20 GHSA-4343-3cxx-2jqg: The monitoring probe display in spacewalk-java before 2
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
Red Hat
Proxy: Improper monitoring probes input sanitization (ACE)
vendor_redhat·2014-02-10·CVSS 6.0
CVE-2010-2236 [MEDIUM] Proxy: Improper monitoring probes input sanitization (ACE)
Proxy: Improper monitoring probes input sanitization (ACE)
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
Statement: The Red Hat Security Response Team has rated this issue as having Moderate security impact. Satellite 5 is currently in the Production 2 phase of its lifecycle, as such this issue is not currently planned to be addressed in future updates. For additional information, refer to the Satellite Life Cycle: https://access.redhat.com/site/support/policy/updates/satellite page.
Package: Server (Red Hat Satellite 5
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/56952https://bugzilla.redhat.com/attachment.cgi?id=819987&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=607712https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13fhttps://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=c41c87a9dc9dac771eb761dd63ada05b2f9104f9https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.htmlhttp://secunia.com/advisories/56952https://bugzilla.redhat.com/attachment.cgi?id=819987&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=607712https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13fhttps://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=c41c87a9dc9dac771eb761dd63ada05b2f9104f9https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html
2014-04-15
Published