Redhat Subscription Asset Manager vulnerabilities

7 known vulnerabilities affecting redhat/subscription_asset_manager.

Total CVEs
7
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2014-0183MEDIUMCVSS 6.1v1.4.02020-01-02
CVE-2014-0183 [MEDIUM] CWE-79 CVE-2014-0183: Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS v Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
nvd
CVE-2015-7501CRITICALCVSS 9.8v1.3.02017-11-09
CVE-2015-7501 [CRITICAL] CWE-502 CVE-2015-7501: Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualiza Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Ha
nvd
CVE-2014-0029MEDIUMCVSS 6.1v1.0.02017-10-16
CVE-2014-0029 [MEDIUM] CWE-79 CVE-2014-0029: Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-he Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
nvd
CVE-2014-0130HIGHCVSS 7.5KEV≤ 1.3.02014-05-07
CVE-2014-0130 [HIGH] CWE-22 CVE-2014-0130: Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-rend Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
nvd
CVE-2013-6439CRITICALCVSS 9.3v1.0.0v1.1.0+3 more2013-12-23
CVE-2013-6439 [CRITICAL] CWE-287 CVE-2013-6439: Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme wh Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.
nvd
CVE-2013-1823MEDIUMCVSS 4.3≤ 1.2.0v1.0.0+1 more2013-04-02
CVE-2013-1823 [MEDIUM] CWE-79 CVE-2013-1823: Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Man Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
nvd
CVE-2012-6119LOWCVSS 2.1≤ 1.2.0v1.0.0+1 more2013-04-02
CVE-2012-6119 [LOW] CWE-264 CVE-2012-6119: Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not proper Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
nvd