Redhat

Satellite

221 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Published 17.10.2018 01:31:17
  • Last modified 21.11.2024 04:05:17

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit v...

  • EPSS 0.18%
  • Published 17.10.2018 01:31:16
  • Last modified 21.11.2024 04:05:14

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unau...

  • EPSS 0.07%
  • Published 17.10.2018 01:31:16
  • Last modified 21.11.2024 04:05:14

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows un...

  • EPSS 0.09%
  • Published 22.08.2018 15:29:00
  • Last modified 21.11.2024 03:32:03

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially c...

  • EPSS 0.59%
  • Published 20.08.2018 21:29:01
  • Last modified 21.11.2024 03:59:57

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.

  • EPSS 0.53%
  • Published 20.08.2018 21:29:01
  • Last modified 21.11.2024 04:00:08

The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.

Exploit
  • EPSS 1%
  • Published 20.08.2018 19:31:31
  • Last modified 21.11.2024 03:40:16

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be explo...

  • EPSS 67.78%
  • Published 09.08.2018 20:29:00
  • Last modified 21.11.2024 03:42:20

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context ...

  • EPSS 0.58%
  • Published 01.08.2018 13:29:00
  • Last modified 21.11.2024 02:59:44

It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code withi...

  • EPSS 0.21%
  • Published 30.07.2018 15:29:00
  • Last modified 21.11.2024 03:32:03

A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.