5.8

CVE-2017-7513

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Satellite Version 5.0
Redhat ≫ Satellite Version 5.1.1
Redhat ≫ Satellite Version 5.2
Redhat ≫ Satellite Version 5.3
Redhat ≫ Satellite Version 5.4
Redhat ≫ Satellite Version 5.4.1
Redhat ≫ Satellite Version 5.5
Redhat ≫ Satellite Version 5.6
Redhat ≫ Satellite Version 5.7
Redhat ≫ Satellite Version 5.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.378
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat 5.4 2.8 2.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7513
Vendor Advisory
Issue Tracking
https://access.redhat.com/security/cve/cve-2017-7513
Vendor Advisory