cbcvebase.

Redhat Satellite vulnerabilities

232 known vulnerabilities affecting redhat/satellite.

Total CVEs
232
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL30HIGH59MEDIUM115LOW28

Vulnerabilities

Page 9 of 12
CVE-2016-9595P4MEDIUMCVSS 5.5v6.32018-07-27
CVE-2016-9595 [MEDIUM] CWE-377 CVE-2016-9595: A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure tem A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
nvd
CVE-2022-3644P4MEDIUMCVSS 5.5v6.02022-10-25
CVE-2022-3644 [MEDIUM] CWE-256 CVE-2022-3644: The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
nvd
CVE-2017-7513P4MEDIUMCVSS 5.4v5.0v5.1.1+8 more2018-08-22
CVE-2017-7513 [MEDIUM] CWE-295 CVE-2017-7513: It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.
nvd
CVE-2016-3079P4MEDIUMCVSS 6.1v5.72016-04-14
CVE-2016-3079 [MEDIUM] CWE-79 CVE-2016-3079: Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Se
nvd
CVE-2017-15100P4MEDIUMCVSS 6.1v6.42017-11-27
CVE-2017-15100 [MEDIUM] CWE-79 CVE-2017-15100: An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.
nvd
CVE-2018-2800P4MEDIUMCVSS 4.2v5.6v5.7+1 more2018-04-19
CVE-2018-2800 [MEDIUM] CVE-2018-2800: Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported ver Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, JRockit. Successful attacks require human intera
nvd
CVE-2015-0284P4MEDIUMCVSS 5.4v5.72016-04-14
CVE-2015-0284 [MEDIUM] CVE-2015-0284: Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 al Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
nvd
CVE-2018-16887P4MEDIUMCVSS 5.4v6.02019-01-13
CVE-2018-16887 [MEDIUM] CWE-79 CVE-2018-16887: A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF t
nvd
CVE-2017-7538P4MEDIUMCVSS 5.4fixed in 5.82018-07-26
CVE-2017-7538 [MEDIUM] CWE-79 CVE-2017-7538: A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organization's name could exploit this flaw to perform XSS attacks against other Satellite users.
nvd
CVE-2015-5233P4MEDIUMCVSS 4.2v6.12016-04-11
CVE-2015-5233 [MEDIUM] CWE-264 CVE-2015-5233: Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allo Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual
nvd
CVE-2026-5138P4MEDIUMCVSS 4.3≥ 6.16, < 6.16.10≥ 6.17, < 6.17.9+2 more2026-07-01
CVE-2026-5138 [MEDIUM] CWE-639 CVE-2026-5138: A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross- A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the
nvd
CVE-2016-2104P4MEDIUMCVSS 6.1v5.72017-04-13
CVE-2016-2104 [MEDIUM] CWE-79 CVE-2016-2104: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the package_name, (3) search_subscribed_channels, or (4) channel_filter parameter to software/packages/NameOverview.do; or unspecified vectors related to (5) or
nvd
CVE-2016-3080P4MEDIUMCVSS 6.1v5.72016-08-05
CVE-2016-3080 [MEDIUM] CWE-79 CVE-2016-3080: Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote at Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters, related to display of monitoring probes.
nvd
CVE-2016-3097P4MEDIUMCVSS 6.1v5.72016-08-05
CVE-2016-3097 [MEDIUM] CWE-79 CVE-2016-3097: Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote at Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.
nvd
CVE-2014-8168P4MEDIUMCVSS 6.1v6.02017-08-28
CVE-2014-8168 [MEDIUM] CWE-284 CVE-2014-8168: Red Hat Satellite 6 allows local users to access mongod and delete pulp_database. Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
nvd
CVE-2012-1145P4MEDIUMCVSS 5.0v5.42012-06-16
CVE-2012-1145 [MEDIUM] CWE-287 CVE-2012-1145: spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly a spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads.
nvd
CVE-2018-2678P4MEDIUMCVSS 4.3v5.6v5.7+1 more2018-01-18
CVE-2018-2678 [MEDIUM] CVE-2018-2678: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,
nvd
CVE-2018-2663P4MEDIUMCVSS 4.3v5.6v5.7+1 more2018-01-18
CVE-2018-2663 [MEDIUM] CVE-2018-2663: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: L Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Jav
nvd
CVE-2018-2581P4MEDIUMCVSS 4.7v5.6v5.7+1 more2018-01-18
CVE-2018-2581 [MEDIUM] CVE-2018-2581: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the at
nvd
CVE-2018-2588P4MEDIUMCVSS 4.3v5.6v5.7+1 more2018-01-18
CVE-2018-2588 [MEDIUM] CVE-2018-2588: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: L Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE,
nvd
Redhat Satellite vulnerabilities | cvebase