Redhat

Satellite

223 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 19.04.2018 02:29:03
  • Zuletzt bearbeitet 06.05.2025 15:15:55

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vuln...

  • EPSS 0.1%
  • Veröffentlicht 19.04.2018 02:29:03
  • Zuletzt bearbeitet 21.11.2024 04:04:29

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerabil...

  • EPSS 0.29%
  • Veröffentlicht 19.04.2018 02:29:03
  • Zuletzt bearbeitet 21.11.2024 04:04:29

Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker wit...

  • EPSS 0.22%
  • Veröffentlicht 16.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:01:28

foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.

  • EPSS 0.15%
  • Veröffentlicht 16.04.2018 14:29:01
  • Zuletzt bearbeitet 12.05.2025 17:37:16

The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies t...

  • EPSS 0.32%
  • Veröffentlicht 05.04.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:59:10

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.

  • EPSS 0.44%
  • Veröffentlicht 04.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:10

A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.

  • EPSS 0.22%
  • Veröffentlicht 14.03.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:07

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

  • EPSS 0.15%
  • Veröffentlicht 12.03.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:56

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middl...

  • EPSS 0.23%
  • Veröffentlicht 27.02.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:08

When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.