Proxy: Improper monitoring probes input sanitization (ACE)
Published Apr 15, 2014
6.0
MEDIUMCVSS 2.0
EPSS 3.06%
Description
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
Affected products
No data.
- 5.3
- 4.0
- 4.1
- 4.2
- 5.1
- 5.2
- 5.3
- ≤ 2.1.147-1
No data.
Red Hat Satellite 5
Server
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 5 | Server | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Security Response Team has rated this issue as having Moderate security impact. Satellite 5 is currently in the Production 2 phase of its lifecycle, as such this issue is not currently planned to be addressed in future updates. For additional information, refer to the Satellite Life Cycle: https://access.redhat.com/site/support/policy/updates/satellite page.
References (9)
- http://secunia.com/advisories/56952 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- https://access.redhat.com/security/cve/CVE-2010-2236 Vendor Advisory
- https://bugzilla.redhat.com/attachment.cgi?id=819987&action=diff x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=607712 x_refsource_CONFIRMIssue Tracking
- https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13f x_refsource_CONFIRMExploitPatch
- https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=c41c87a9dc9dac771eb761dd63ada05b2f9104f9 x_refsource_CONFIRMExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2010-2236
- https://www.cve.org/CVERecord?id=CVE-2010-2236
- https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html vendor-advisoryx_refsource_SUSE
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/56952 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2010-2236 | Vendor Advisory | |
| https://bugzilla.redhat.com/attachment.cgi?id=819987&action=diff | x_refsource_MISC | |
| https://bugzilla.redhat.com/show_bug.cgi?id=607712 | x_refsource_CONFIRMIssue Tracking | |
| https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13f | x_refsource_CONFIRMExploitPatch | |
| https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=c41c87a9dc9dac771eb761dd63ada05b2f9104f9 | x_refsource_CONFIRMExploitPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-2236 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-2236 | ||
| https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html | vendor-advisoryx_refsource_SUSE |
Change history (0)
No recorded changes yet.