Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23666
HistoryApr 10, 2020 - 12:33 a.m.

Information Disclosure

2020-04-1000:33:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.003

Percentile

71.2%

mod_perl is vulnerable to information disclosure. It was discovered that Red Hat Network Satellite Server shipped with an XML-RPC script, manzier.pxt, which had a single hard-coded authentication key. A remote attacker who is able to connect to the Satellite Server XML-RPC service could use this flaw to obtain limited information about Satellite Server users, such as login names, associated email addresses, internal user IDs, and partial information about entitlements.

EPSS

0.003

Percentile

71.2%