Redhat
Redhat Subscription Asset Manager: vulnerabilidades y CVE
Redhat Subscription Asset Manager tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2014-0130 | Alta (7.5) | 54% | ⚠ Explotación activa | 7 may 2014 | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2012-6685 | Alta (7.5) | 2.2% | — | 19 feb 2020 | Nokogiri before 1.5.4 is vulnerable to XXE attacks |
| CVE-2014-0183 | Media (6.1) | 0.66% | — | 2 ene 2020 | Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. |
| CVE-2014-0026 | Media (6.5) | 0.43% | — | 11 dic 2019 | katello-headpin is vulnerable to CSRF in REST API |
| CVE-2013-6461 | Media (6.5) | 2.2% | — | 5 nov 2019 | Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits |
| CVE-2013-6460 | Media (6.5) | 2.1% | — | 5 nov 2019 | Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents |
| CVE-2015-7501 | Crítica (9.8) | 86% | — | 9 nov 2017 | Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x;… |
| CVE-2014-0029 | Media (6.1) | 0.75% | — | 16 oct 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters. |
| CVE-2014-0130 | Alta (7.5) | 54% | ⚠ Explotación activa | 7 may 2014 | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route… |
| CVE-2013-6439 | Alta (9.3) | 1.6% | — | 23 dic 2013 | Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors. |
| CVE-2013-1823 | Media (4.3) | 1.9% | — | 2 abr 2013 | Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field. |
| CVE-2012-6119 | Baja (2.1) | 0.42% | — | 2 abr 2013 | Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230