CVE-2019-3891
- EPSS 0.04%
- Veröffentlicht 15.04.2019 12:31:42
- Zuletzt bearbeitet 21.11.2024 04:42:48
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify th...
- EPSS 0.18%
- Veröffentlicht 11.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:41
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host regi...
CVE-2019-3893
- EPSS 0.39%
- Veröffentlicht 09.04.2019 16:29:02
- Zuletzt bearbeitet 21.11.2024 04:42:48
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resou...
CVE-2018-12547
- EPSS 0.79%
- Veröffentlicht 11.02.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:24
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly ...
CVE-2018-12549
- EPSS 0.72%
- Veröffentlicht 11.02.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:25
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.
CVE-2019-7317
- EPSS 0.57%
- Veröffentlicht 04.02.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:00
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVE-2018-14666
- EPSS 0.35%
- Veröffentlicht 22.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:32
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red...
CVE-2019-2449
- EPSS 2.42%
- Veröffentlicht 16.01.2019 19:30:32
- Zuletzt bearbeitet 21.11.2024 04:40:53
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protoco...
CVE-2019-2422
- EPSS 0.33%
- Veröffentlicht 16.01.2019 19:30:31
- Zuletzt bearbeitet 21.11.2024 04:40:50
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker...
CVE-2018-16887
- EPSS 0.25%
- Veröffentlicht 13.01.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:32
A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Rep...