CVE Vulnerabilities

CVE-2009-4139

Origin Validation Error

Published: Jul 27, 2011 | Modified: Apr 29, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or escalating privileges by modifying existing user accounts to have administrator access.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
Network_satellite_serverRedhat5.3.0 (including)5.3.0 (including)
Network_satellite_serverRedhat5.4.0 (including)5.4.0 (including)
Network_satellite_serverRedhat5.4.1 (including)5.4.1 (including)
Spacewalk-javaRedhat1.2.39 (including)1.2.39 (including)

References