CVE-2016-3072
published 2016-06-07CVE-2016-3072: Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated…
PriorityP354high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.84%
76.5th percentile
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| katello | katello | >= 0 < 2.4.3 | 2.4.3 |
| katello | katello | 0 – 3.10 | — |
| redhat | satellite | — | — |
| the_foreman_project | katello | — | — |
| theforeman | katello | >= 3.10.0 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
ghsa8.8HIGH
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Katello SQL Injection vulnerabilities
ghsa·2022-05-14
CVE-2016-3072 [HIGH] CWE-89 Katello SQL Injection vulnerabilities
Katello SQL Injection vulnerabilities
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
OSV
Katello SQL Injection vulnerabilities
osv·2022-05-14
CVE-2016-3072 [HIGH] Katello SQL Injection vulnerabilities
Katello SQL Injection vulnerabilities
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
GHSA
katello SQL Injection vulnerability
ghsa·2022-05-13·CVSS 8.8
CVE-2018-14623 [HIGH] CWE-209 katello SQL Injection vulnerability
katello SQL Injection vulnerability
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.
OSV
katello SQL Injection vulnerability
osv·2022-05-13·CVSS 8.8
CVE-2018-14623 [HIGH] katello SQL Injection vulnerability
katello SQL Injection vulnerability
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.
Red Hat
katello: SQL inject in errata-related REST API
vendor_redhat·2018-12-12·CVSS 8.8
CVE-2018-14623 [HIGH] CWE-89 katello: SQL inject in errata-related REST API
katello: SQL inject in errata-related REST API
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs.
Package: katello (Red Hat Subscription Asset Manager) - Will not fix
Red Hat
Katello: Authenticated sql injection via sort_by and sort_order request parameter
vendor_redhat·2016-05-16·CVSS 8.8
CVE-2016-3072 [HIGH] CWE-89 Katello: Authenticated sql injection via sort_by and sort_order request parameter
Katello: Authenticated sql injection via sort_by and sort_order request parameter
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
An input sanitization flaw was found in the scoped search parameters sort_by and sort_order in the REST API. An authenticated user could use this flaw to perform an SQL injection attack on the Katello back end database.
Package: katello (Red Hat Subscription Asset Manager) - Not affected
No detection rules found.
No public exploits indexed.
2016-06-07
Published