cbcvebase.

Redhat Satellite vulnerabilities

232 known vulnerabilities affecting redhat/satellite.

Total CVEs
232
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL30HIGH59MEDIUM115LOW28

Vulnerabilities

Page 5 of 12
CVE-2026-48864P3HIGHCVSS 7.8v6.02026-05-26
CVE-2026-48864 [HIGH] CWE-787 CVE-2026-48864: A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-c A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result
nvd
CVE-2019-10198P3MEDIUMCVSS 6.5v6.62019-07-31
CVE-2019-10198 [MEDIUM] CWE-592 CVE-2019-10198: An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, co An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
nvd
CVE-2015-8126P3HIGHCVSS 7.5v5.7v5.62015-11-13
CVE-2015-8126 [HIGH] CWE-120 CVE-2015-8126: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1. Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value
nvd
CVE-2018-1517P3HIGHCVSS 7.5v5.6v5.7+1 more2018-08-20
CVE-2018-1517 [HIGH] CWE-20 CVE-2018-1517: A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.
nvd
CVE-2019-10245P3HIGHCVSS 7.5v5.82019-04-19
CVE-2019-10245 [HIGH] CWE-20 CVE-2019-10245: In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a metho In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
nvd
CVE-2026-5135P3MEDIUMCVSS 6.5≥ 6.16, < 6.16.10≥ 6.17, < 6.17.9+2 more2026-07-01
CVE-2026-5135 [MEDIUM] CWE-639 CVE-2026-5135: A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user w A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for u
nvd
CVE-2018-2634P3MEDIUMCVSS 6.8v5.6v5.7+1 more2018-01-18
CVE-2018-2634 [MEDIUM] CVE-2018-2634: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Sup Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vuln
nvd
CVE-2016-1000338P3HIGHCVSS 7.5v6.42018-06-01
CVE-2016-1000338 [HIGH] CWE-347 CVE-2016-1000338: In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encodin In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.
nvd
CVE-2019-3891P3HIGHCVSS 7.8v6.42019-04-15
CVE-2019-3891 [HIGH] CWE-532 CVE-2019-3891: It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satelli It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from
nvd
CVE-2010-2236P3MEDIUMCVSS 6.0v4.0v4.1+4 more2014-04-15
CVE-2010-2236 [MEDIUM] CWE-20 CVE-2010-2236: The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
nvd
CVE-2026-5142P3MEDIUMCVSS 6.5≥ 6.18, < 6.18.7≥ 6.16, < 6.16.10+2 more2026-07-01
CVE-2026-5142 [MEDIUM] CWE-639 CVE-2026-5142: A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive inform
nvd
CVE-2018-2582P3MEDIUMCVSS 6.5v5.82018-01-18
CVE-2018-2582 [MEDIUM] CVE-2018-2582: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks re
nvd
CVE-2012-6685P3HIGHCVSS 7.5v6.02020-02-19
CVE-2012-6685 [HIGH] CWE-776 CVE-2012-6685: Nokogiri before 1.5.4 is vulnerable to XXE attacks Nokogiri before 1.5.4 is vulnerable to XXE attacks
nvd
CVE-2019-11775P3HIGHCVSS 7.4v5.82019-07-30
CVE-2019-11775 [HIGH] CWE-367 CVE-2019-11775: All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privat All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one va
nvd
CVE-2018-14666P3HIGHCVSS 7.2≥ 6.0, ≤ 6.42019-01-22
CVE-2018-14666 [HIGH] CWE-285 CVE-2018-14666: An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
nvd
CVE-2018-2799P3MEDIUMCVSS 5.3v5.6v5.7+1 more2018-04-19
CVE-2018-2799 [MEDIUM] CVE-2018-2799: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE E
nvd
CVE-2018-2794P3HIGHCVSS 7.7v5.6v5.7+1 more2018-04-19
CVE-2018-2794 [HIGH] CVE-2018-2794: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supporte Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162, 10 and JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, JRockit executes to compromise Java SE, JRockit. Successful
nvd
CVE-2018-1077P3HIGHCVSS 7.5v5.02018-03-14
CVE-2018-1077 [HIGH] CWE-611 CVE-2018-1077: Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensi Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.
nvd
CVE-2018-1096P3MEDIUMCVSS 6.5v6.42018-04-05
CVE-2018-1096 [MEDIUM] CWE-89 CVE-2018-1096: An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1 An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
nvd
CVE-2026-9150P3MEDIUMCVSS 6.5v6.02026-05-20
CVE-2026-9150 [MEDIUM] CWE-121 CVE-2026-9150: A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debi A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
nvd
Redhat Satellite vulnerabilities | cvebase