Lucene search

K
cveRedhatCVE-2010-1171
HistoryApr 18, 2011 - 5:55 p.m.

CVE-2010-1171

2011-04-1817:55:00
CWE-264
redhat
web.nvd.nist.gov
37
red hat
rhn satellite
cve-2010-1171
xml-rpc
api
vulnerability
nvd
security
configuration
package group
denial of service

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

AI Score

6.7

Confidence

Low

EPSS

0.007

Percentile

79.6%

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.

Affected configurations

Nvd
Node
redhatsatelliteMatch5.3
OR
redhatsatelliteMatch5.4
VendorProductVersionCPE
redhatsatellite5.3cpe:2.3:a:redhat:satellite:5.3:*:*:*:*:*:*:*
redhatsatellite5.4cpe:2.3:a:redhat:satellite:5.4:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

AI Score

6.7

Confidence

Low

EPSS

0.007

Percentile

79.6%