Red Hat Satellite 6.3

CPE Details

Red Hat Satellite 6.3
6.3
2023-09-22
17h01 +00:00
2023-09-22
17h01 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:satellite:6.3:-:*:*:*:*:*:*

Informations

Vendor

redhat

Product

satellite

Version

6.3

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-4320 2023-12-18 13h43 +00:00 An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.
7.6
High
CVE-2023-0462 2023-09-20 13h40 +00:00 An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
9.1
Critical
CVE-2019-0223 2019-04-23 13h57 +00:00 While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
7.4
High
CVE-2018-14666 2019-01-22 14h00 +00:00 An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
7.2
High
CVE-2016-8639 2018-08-01 11h00 +00:00 It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
6.1
Medium
CVE-2016-9595 2018-07-27 16h00 +00:00 A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
7.3
High
CVE-2017-12175 2018-07-26 15h00 +00:00 Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
5.4
Medium
CVE-2017-2672 2018-06-21 11h00 +00:00 A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
8.8
High
CVE-2017-2667 2018-03-12 15h00 +00:00 Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
8.1
High
CVE-2016-4996 2017-07-14 18h00 +00:00 discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.
7
High