CVE-2010-4179
published 2010-12-07CVE-2010-4179: The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.79%
75.8th percentile
The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG Management Console (cumin) can submit jobs for users, which creates a trusted channel with insufficient access control that allows local users with the ability to publish to a broker to run jobs as arbitrary users via Condor QMF plug-ins.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
plugin: enable QUEUE_ALL_USERS_TRUSTED for Submit/Hold/Release/Remove ops
vendor_redhat·2010-11-30·CVSS 7.5
CVE-2010-4179 [HIGH] CWE-284 plugin: enable QUEUE_ALL_USERS_TRUSTED for Submit/Hold/Release/Remove ops
plugin: enable QUEUE_ALL_USERS_TRUSTED for Submit/Hold/Release/Remove ops
The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG Management Console (cumin) can submit jobs for users, which creates a trusted channel with insufficient access control that allows local users with the ability to publish to a broker to run jobs as arbitrary users via Condor QMF plug-ins.
GHSA
GHSA-p347-c2jx-fcmf: The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1
ghsa_unreviewed·2022-05-13
CVE-2010-4179 [HIGH] GHSA-p347-c2jx-fcmf: The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1
The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG Management Console (cumin) can submit jobs for users, which creates a trusted channel with insufficient access control that allows local users with the ability to publish to a broker to run jobs as arbitrary users via Condor QMF plug-ins.
Suricata
ET WEB_SERVER Possible HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow Attempt
suricata·2010-07-30
CVE-2009-4179 ET WEB_SERVER Possible HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow Attempt
ET WEB_SERVER Possible HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow Attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow Attempt"; flow:established,to_server; http.method; content:"GET"; nocase; http.uri; content:"/OvCgi/ovalarm.exe"; nocase; fast_pattern; content:"OVABverbose="; nocase; distance:0; pcre:"/^(1|on|true)/Ri"; http.accept_lang; isdataat:100,relative; reference:cve,2009-4179; classtype:web-application-attack; sid:2010704; rev:10; metadata:created_at 2010_07_30, cve CVE_2009_4179, confidence Low, signature_severity Major, updated_at 2020_11_07;)
http://secunia.com/advisories/42406http://www.redhat.com/support/errata/RHSA-2010-0921.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0922.htmlhttp://www.securitytracker.com/id?1024806http://www.vupen.com/english/advisories/2010/3091https://bugzilla.redhat.com/show_bug.cgi?id=654856http://secunia.com/advisories/42406http://www.redhat.com/support/errata/RHSA-2010-0921.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0922.htmlhttp://www.securitytracker.com/id?1024806http://www.vupen.com/english/advisories/2010/3091https://bugzilla.redhat.com/show_bug.cgi?id=654856
2010-12-07
Published