Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Network_satellite_server | Redhat | 5.4 (including) | 5.4 (including) |
Red Hat Network Satellite Server v 5.4 | RedHat | spacewalk-backend-0:1.2.13-26.2.el5sat | * |
Red Hat Network Satellite Server v 5.4 | RedHat | spacewalk-java-0:1.2.39-35.1.el5sat | * |