Redhat

Satellite

228 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 05.04.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:59:10

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.

  • EPSS 0.37%
  • Veröffentlicht 04.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:10

A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.

  • EPSS 0.22%
  • Veröffentlicht 14.03.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:07

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

  • EPSS 0.11%
  • Veröffentlicht 12.03.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:56

Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middl...

  • EPSS 0.23%
  • Veröffentlicht 27.02.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:08

When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.

  • EPSS 0.09%
  • Veröffentlicht 09.02.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:06:18

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

  • EPSS 0.19%
  • Veröffentlicht 09.02.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:06:18

In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4

  • EPSS 9.26%
  • Veröffentlicht 06.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:03

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMappe...

  • EPSS 0.07%
  • Veröffentlicht 18.01.2018 02:29:22
  • Zuletzt bearbeitet 21.11.2024 04:04:11

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploit...

  • EPSS 0.07%
  • Veröffentlicht 18.01.2018 02:29:22
  • Zuletzt bearbeitet 21.11.2024 04:04:13

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthen...