CVE-2014-3595
Published Sep 22, 2014
Last updated 3 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:satellite:5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3CCE54F9-0195-4E9D-A15F-3947EA0EBED7" }, { "criteria": "cpe:2.3:a:redhat:satellite:5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B6D3920-6A7D-4AF8-A620-80C89FF454F2" }, { "criteria": "cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4840254-CC76-4113-BC61-360BD15582B9" }, { "criteria": "cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2A12684-8CB8-49A6-8E06-1E1AE5B43E87" }, { "criteria": "cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46E05B39-84D0-4208-A299-2B6B999FA482" }, { "criteria": "cpe:2.3:a:redhat:spacewalk-java:1.2.39:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8CF0A4D-0501-4DEC-AADD-4A157E5960D8" }, { "criteria": "cpe:2.3:a:redhat:spacewalk-java:1.7.54:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE0CD9A2-DE09-4281-8529-EB7117293918" }, { "criteria": "cpe:2.3:a:redhat:spacewalk-java:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66B5B0A5-C60C-4D9A-834C-B670B645CF26" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:suse:manager:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C9E2D37-9F56-49E0-BB28-56FB755CE078" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B94190DE-DF41-4202-B513-DE3ABDED35FE" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:suse:manager_server:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4E8CE0B-23E7-45BF-AAFB-AD12DC7EB0F0" } ], "operator": "OR" } ] } ]