Skip to main content

Vendor/product archive

redhat / satellite CVEs

Beta · best-effort

233 CVEs tagged to redhat / satellite26 Critical, 59 High, 118 Medium, 30 Low, 0 Unrated.

CVE-2019-0223

Published Apr 23, 2019

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a p…

CVSS 7.4 · High

CVE-2019-3891

Published Apr 15, 2019

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3845

Published Apr 11, 2019

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional a…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3893

Published Apr 9, 2019

In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the aff…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14666

Published Jan 22, 2019

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, indepen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-2449

Published Jan 16, 2019

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability a…

CVSS 3.1 · Low

CVE-2018-16887

Published Jan 13, 2019

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3214

Published Oct 17, 2018

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182…

CVSS 5.3 · Medium

CVE-2018-3183

Published Oct 17, 2018

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported versions that are affected are Java SE: 8u182 and 11; Java…

CVSS 9.0 · Critical

CVE-2018-3180

Published Oct 17, 2018

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and…

CVSS 5.6 · Medium

CVE-2018-3169

Published Oct 17, 2018

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u191, 8u182 and 11; Java SE…

CVSS 8.3 · High

CVE-2018-3149

Published Oct 17, 2018

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and…

CVSS 8.3 · High

CVE-2018-3139

Published Oct 17, 2018

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11…

CVSS 3.1 · Low

CVE-2018-3136

Published Oct 17, 2018

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11;…

CVSS 3.4 · Low

CVE-2017-7513

Published Aug 22, 2018

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attack…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10931

Published Aug 9, 2018

It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privil…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7514

Published Jul 30, 2018

A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 233 CVEsPage 4 of 10