cbcvebase.

Redhat Satellite vulnerabilities

232 known vulnerabilities affecting redhat/satellite.

Total CVEs
232
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL30HIGH59MEDIUM115LOW28

Vulnerabilities

Page 10 of 12
CVE-2017-7514P4MEDIUMCVSS 5.4fixed in 5.8.02018-07-30
CVE-2017-7514 [MEDIUM] CWE-79 CVE-2017-7514: A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat S A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.
nvd
CVE-2012-0059P4MEDIUMCVSS 4.9v5.42014-02-05
CVE-2012-0059 [MEDIUM] CWE-209 CVE-2012-0059: A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a syste A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.
nvd
CVE-2016-2103P4MEDIUMCVSS 6.1v5.72016-04-14
CVE-2016-2103 [MEDIUM] CWE-79 CVE-2016-2103: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.
nvd
CVE-2014-0141P4MEDIUMCVSS 6.1v6.0.32017-08-28
CVE-2014-0141 [MEDIUM] CWE-79 CVE-2014-0141: Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3. Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.
nvd
CVE-2018-2677P4MEDIUMCVSS 4.3v5.6v5.7+1 more2018-01-18
CVE-2018-2677 [MEDIUM] CVE-2018-2677: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supp Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2017-12175P4MEDIUMCVSS 5.4fixed in 6.52018-07-26
CVE-2017-12175 [MEDIUM] CWE-79 CVE-2017-12175: Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter a Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
nvd
CVE-2017-10689P4MEDIUMCVSS 5.5v6.42018-02-09
CVE-2017-10689 [MEDIUM] CWE-269 CVE-2017-10689: In previous versions of Puppet Agent it was possible to install a module with world writable permiss In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
nvd
CVE-2018-2940P4MEDIUMCVSS 4.3v5.6v5.7+1 more2018-07-18
CVE-2018-2940 [MEDIUM] CVE-2018-2940: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Suc
nvd
CVE-2014-3595P4MEDIUMCVSS 4.3v5.4v5.5+1 more2014-09-22
CVE-2014-3595 [MEDIUM] CWE-79 CVE-2014-3595: Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk an Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.
nvd
CVE-2014-0241P4MEDIUMCVSS 5.5v6.02019-12-13
CVE-2014-0241 [MEDIUM] CWE-522 CVE-2014-0241: rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
nvd
CVE-2013-2101P4MEDIUMCVSS 5.4v6.02019-12-03
CVE-2013-2101 [MEDIUM] CWE-79 CVE-2013-2101: Katello has multiple XSS issues in various entities Katello has multiple XSS issues in various entities
nvd
CVE-2015-1931P4MEDIUMCVSS 5.5v5.6v5.72022-09-29
CVE-2015-1931 [MEDIUM] CWE-312 CVE-2015-1931: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
nvd
CVE-2017-10105P4MEDIUMCVSS 4.3v5.82017-08-08
CVE-2017-10105 [MEDIUM] CVE-2017-10105: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versi Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than
nvd
CVE-2024-4812P4MEDIUMCVSS 4.8v6.02024-06-05
CVE-2024-4812 [MEDIUM] CWE-79 CVE-2024-4812: A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScri A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections.
nvd
CVE-2013-4415P4MEDIUMCVSS 4.3v5.62014-02-14
CVE-2013-4415 [MEDIUM] CWE-79 CVE-2013-4415: Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) whereCriteria variable in a software channels search; (2) end_year, (3) start_hour, (4) end_am_pm, (5) end_day, (6) end_hour, (7) end_minute, (8) end_month, (9) end_year, (10)
nvd
CVE-2017-10295P4MEDIUMCVSS 4.0v5.82017-10-19
CVE-2017-10295 [MEDIUM] CVE-2017-10295: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: N Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java SE, Java SE
nvd
CVE-2026-13316P4MEDIUMCVSS 4.4≥ 6.0, ≤ 6.192026-06-30
CVE-2026-13316 [MEDIUM] CWE-918 CVE-2026-13316: A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and ht A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
nvd
CVE-2019-2996P4MEDIUMCVSS 4.2v5.82019-10-16
CVE-2019-2996 [MEDIUM] CVE-2019-2996: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). Th Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u221; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require hu
nvd
CVE-2013-1869P4MEDIUMCVSS 4.3v5.62014-04-01
CVE-2013-1869 [MEDIUM] CWE-20 CVE-2013-1869: CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via the return_url parameter.
nvd
CVE-2014-3654P4MEDIUMCVSS 4.3v5.5v5.62014-11-03
CVE-2014-3654 [MEDIUM] CWE-79 CVE-2014-3654: Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3) admin/multiorg/OrgUsers.do.
nvd
Redhat Satellite vulnerabilities | cvebase