4.3
CVSSv2

CVE-2014-3654

Published: 03/11/2014 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3) admin/multiorg/OrgUsers.do.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat spacewalk-java 2.0.2

redhat satellite 5.6

redhat satellite 5.5

redhat satellite with embedded oracle 5.5

suse manager server -

suse manager 1.7

Vendor Advisories

Stored and reflected cross-site scripting (XSS) flaws were found in the way spacewalk-java displayed certain information By sending a specially crafted request to Satellite, a remote, authenticated attacker could embed HTML content into the stored data, allowing them to inject malicious content into the web page that is used to view that data ...