CVE Vulnerabilities

CVE-2010-1171

Published: Apr 18, 2011 | Modified: Feb 19, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.

Affected Software

Name Vendor Start Version End Version
Satellite Redhat 5.3 (including) 5.3 (including)
Satellite Redhat 5.4 (including) 5.4 (including)

References