[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2015:0033-01 -- Redhat postgresql92, postgresql92-postgresql, satellite-repo, scl-utils, spacewalk-setup-postgresql, spacewalk-web, MessageQueue, NOCpulsePlugins, NPalert, ProgAGoGo, PyYAML, SNMPAlerts, SatConfig-bootstrap, SatConfig-bootstrap-server, SatConfig-cluster, SatConfig-general, SatConfig-generator, SatConfig-installer, SatConfig-spread, SputLite, ace-editor, antlr, apache-commons-beanutils, apache-commons-cli, bootstrap, bootstrap-datepicker, c3p0, cglib, cobbler, cobbler-loaders, concurrent, cx_Oracle, dojo, dom4j, dwr, editarea, eventReceivers, font-awesome, glassfish-jsf, hibernate3, jabberd, jabberpy, jakarta-commons-chain, jakarta-commons-codec, jakarta-commons-digester, jakarta-commons-el, jakarta-commons-fileupload, jakarta-commons-io, jakarta-commons-lang, jakarta-commons-logging, jakarta-commons-logging-jboss, jakarta-commons-parent-11, jakarta-commons-validator, jakarta-oro, jakarta-taglibs-standard, java-1.6.0-ibm, javassist, jboss-javaee, jcommon, jdom, jfreechart, jpam, jquery-timepicker, jquery-ui, libapreq2, libgsasl, libntlm, libreadline-java, libyaml, momentjs, nocpulse-common, nocpulse-db-perl, nutch, objectweb-asm, oracle-config, oracle-instantclient, oracle-instantclient-selinux, oracle-selinux, osad, oscache, patternfly1, perl-Apache-DBI, perl-BerkeleyDB, perl-Cache-Cache, perl-Class-MethodMaker, perl-Class-Singleton, perl-Config-IniFiles, perl-Convert-BinHex, perl-Crypt-DES, perl-Crypt-GeneratePassword, perl-DBD-Oracle, perl-DateTime, perl-Email-Date-Format, perl-Filesys-Df, perl-HTML-TableExtract, perl-IO-stringy, perl-IPC-ShareLite, perl-List-MoreUtils, perl-MIME-Lite, perl-MIME-Types, perl-MIME-tools, perl-Mail-RFC822-Address, perl-NOCpulse-CLAC, perl-NOCpulse-Debug, perl-NOCpulse-Gritch, perl-NOCpulse-Object, perl-NOCpulse-OracleDB, perl-NOCpulse-PersistentConnection, perl-NOCpulse-Probe, perl-NOCpulse-ProcessPool, perl-NOCpulse-Scheduler, perl-NOCpulse-SetID, perl-NOCpulse-Utils, perl-Net-INET6Glue, perl-Net-IPv4Addr, perl-Net-SNMP, perl-Params-Validate, perl-SOAP-Lite, perl-Satcon, perl-TermReadKey, perl-XML-Generator, pwstrength-bootstrap, python-debian, python-gzipstream, python-psycopg2, quartz, redstone-xmlrpc, rhn-i18n-guides, rhn-i18n-release-notes, rhn-solaris-bootstrap, rhnlib, rhnpush, roboto, satellite-branding, satellite-doc-indexes, satellite-schema, scdb, select2, select2-bootstrap-css, simple-core, sitemesh, spacecmd, spacewalk, spacewalk-admin, spacewalk-backend, spacewalk-certs-tools, spacewalk-config, spacewalk-java, spacewalk-monitoring, spacewalk-monitoring-selinux, spacewalk-reports, spacewalk-schema, spacewalk-search, spacewalk-selinux, spacewalk-setup, spacewalk-setup-jabberd, spacewalk-slf4j, spacewalk-ssl-cert-check, spacewalk-utils, ssl_bridge, status_log_acceptor, stringtree-json, struts, tanukiwrapper, tsdb, udns, xalan-j2

ID: oval:org.secpod.oval:def:505826Date: (C)2021-02-05   (M)2023-02-20
Class: PATCHFamily: unix




Red Hat Satellite provides a solution to organizations requiring absolute control over and privacy of the maintenance and package deployment of their servers. It allows organizations to utilize the benefits of Red Hat Network without having to provide public Internet access to their servers or other client systems. This update introduces Red Hat Satellite 5.7.0. For the full list of new features included in this release, see the Release Notes document at: https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/5.7/ Note: Red Hat Satellite 5.7 and Red Hat Satellite Proxy 5.7 are available for installation on Red Hat Enterprise Linux Server 6. For full details, including supported architecture combinations, refer to the Red Hat Satellite 5.7 Installation Guide. This update fixes the following security issues: Multiple stored cross-site scripting flaw were found in the handling of XML data passed to Satellite via the REST API. By sending a specially crafted request to Satellite, a remote, authenticated attacker could embed HTML content into the stored data, allowing them to inject malicious content into the web page that is used to view that data. A stored cross-site scripting flaw was found in the System Groups field. By sending a specially crafted request to Satellite, a remote, authenticated attacker could embed HTML content into the stored data, allowing them to inject malicious content into the web page that is used to view that data. Red Hat would like to thank Mickael Gallier for reporting these issues. All users of Red Hat Satellite are advised to install this newly released version.

Platform:
Red Hat Enterprise Linux 6
Product:
postgresql92
postgresql92-postgresql
satellite-repo
scl-utils
spacewalk-setup-postgresql
spacewalk-web
MessageQueue
NOCpulsePlugins
NPalert
ProgAGoGo
PyYAML
SNMPAlerts
SatConfig-bootstrap
SatConfig-bootstrap-server
SatConfig-cluster
SatConfig-general
SatConfig-generator
SatConfig-installer
SatConfig-spread
SputLite
ace-editor
antlr
apache-commons-beanutils
apache-commons-cli
bootstrap
bootstrap-datepicker
c3p0
cglib
cobbler
cobbler-loaders
concurrent
cx_Oracle
dojo
dom4j
dwr
editarea
eventReceivers
font-awesome
glassfish-jsf
hibernate3
jabberd
jabberpy
jakarta-commons-chain
jakarta-commons-codec
jakarta-commons-digester
jakarta-commons-el
jakarta-commons-fileupload
jakarta-commons-io
jakarta-commons-lang
jakarta-commons-logging
jakarta-commons-logging-jboss
jakarta-commons-parent-11
jakarta-commons-validator
jakarta-oro
jakarta-taglibs-standard
java-1.6.0-ibm
javassist
jboss-javaee
jcommon
jdom
jfreechart
jpam
jquery-timepicker
jquery-ui
libapreq2
libgsasl
libntlm
libreadline-java
libyaml
momentjs
nocpulse-common
nocpulse-db-perl
nutch
objectweb-asm
oracle-config
oracle-instantclient
oracle-instantclient-selinux
oracle-selinux
osad
oscache
patternfly1
perl-Apache-DBI
perl-BerkeleyDB
perl-Cache-Cache
perl-Class-MethodMaker
perl-Class-Singleton
perl-Config-IniFiles
perl-Convert-BinHex
perl-Crypt-DES
perl-Crypt-GeneratePassword
perl-DBD-Oracle
perl-DateTime
perl-Email-Date-Format
perl-Filesys-Df
perl-HTML-TableExtract
perl-IO-stringy
perl-IPC-ShareLite
perl-List-MoreUtils
perl-MIME-Lite
perl-MIME-Types
perl-MIME-tools
perl-Mail-RFC822-Address
perl-NOCpulse-CLAC
perl-NOCpulse-Debug
perl-NOCpulse-Gritch
perl-NOCpulse-Object
perl-NOCpulse-OracleDB
perl-NOCpulse-PersistentConnection
perl-NOCpulse-Probe
perl-NOCpulse-ProcessPool
perl-NOCpulse-Scheduler
perl-NOCpulse-SetID
perl-NOCpulse-Utils
perl-Net-INET6Glue
perl-Net-IPv4Addr
perl-Net-SNMP
perl-Params-Validate
perl-SOAP-Lite
perl-Satcon
perl-TermReadKey
perl-XML-Generator
pwstrength-bootstrap
python-debian
python-gzipstream
python-psycopg2
quartz
redstone-xmlrpc
rhn-i18n-guides
rhn-i18n-release-notes
rhn-solaris-bootstrap
rhnlib
rhnpush
roboto
satellite-branding
satellite-doc-indexes
satellite-schema
scdb
select2
select2-bootstrap-css
simple-core
sitemesh
spacecmd
spacewalk
spacewalk-admin
spacewalk-backend
spacewalk-certs-tools
spacewalk-config
spacewalk-java
spacewalk-monitoring
spacewalk-monitoring-selinux
spacewalk-reports
spacewalk-schema
spacewalk-search
spacewalk-selinux
spacewalk-setup
spacewalk-setup-jabberd
spacewalk-slf4j
spacewalk-ssl-cert-check
spacewalk-utils
ssl_bridge
status_log_acceptor
stringtree-json
struts
tanukiwrapper
tsdb
udns
xalan-j2
Reference:
RHSA-2015:0033-01
CVE-2014-7811
CVE-2014-7812
CVE    2
CVE-2014-7811
CVE-2014-7812
CPE    168
cpe:/a:apache:jakarta-commons-chain
cpe:/a:javascript:dom4j
cpe:/a:javascript:momentjs
cpe:/a:perl:perl-nocpulse-processpool
...

© SecPod Technologies