Red Hat Subscription Asset Manager 1.1.0

CPE Details

Red Hat Subscription Asset Manager 1.1.0
1.1.0
2013-04-03
10h22 +00:00
2013-04-09
19h30 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:subscription_asset_manager:1.1.0:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

subscription_asset_manager

Version

1.1.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2014-0130 2014-05-07 10h00 +00:00 Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
7.5
High
CVE-2013-6439 2013-12-23 21h00 +00:00 Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.
9.3
CVE-2012-6119 2013-04-02 22h00 +00:00 Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
2.1
CVE-2013-1823 2013-04-02 22h00 +00:00 Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
4.3