4.3
CVSSv2

CVE-2014-3595

Published: 22/09/2014 Updated: 25/02/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 up to and including 5.6 allows remote malicious users to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat satellite 5.4

redhat satellite 5.5

redhat satellite 5.6

redhat satellite with embedded oracle 5.4

redhat satellite with embedded oracle 5.5

redhat spacewalk-java 1.2.39

redhat spacewalk-java 1.7.54

redhat spacewalk-java 2.0.2

suse manager 1.7

suse manager server -