CVE-2017-7513
- EPSS 0.09%
- Veröffentlicht 22.08.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:03
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially c...
CVE-2018-1517
- EPSS 0.59%
- Veröffentlicht 20.08.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:57
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.
CVE-2018-1656
- EPSS 0.58%
- Veröffentlicht 20.08.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:00:08
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.
CVE-2018-1000632
- EPSS 1.61%
- Veröffentlicht 20.08.2018 19:31:31
- Zuletzt bearbeitet 21.11.2024 03:40:16
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be explo...
CVE-2018-10931
- EPSS 66.91%
- Veröffentlicht 09.08.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:20
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context ...
CVE-2016-8639
- EPSS 0.58%
- Veröffentlicht 01.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:44
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code withi...
CVE-2017-7514
- EPSS 0.21%
- Veröffentlicht 30.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:03
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.
CVE-2016-9595
- EPSS 0.04%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:28
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
CVE-2017-7470
- EPSS 0.73%
- Veröffentlicht 27.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:58
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
CVE-2017-12175
- EPSS 0.47%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:59
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.