
CVE-2013-2056 – Satellite: Inter-Satellite Sync (ISS) does not require authentication/authorization
https://notcve.org/view.php?id=CVE-2013-2056
21 May 2013 — The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call. La operación Inter-Satellite Sync (ISS) en Red Hat Network (RHN) Satellite 5.3, 5.4, y 5.5 no valida adecuadamente la "autenticidad" del cliente, lo que permite a atacantes remotos obtener el contenido de un canal evitando la llamada inicial para la autenticación. Red H... • http://rhn.redhat.com/errata/RHSA-2013-0848.html • CWE-287: Improper Authentication •

CVE-2012-1145 – satellite: remote package upload without authorization
https://notcve.org/view.php?id=CVE-2012-1145
16 Jun 2012 — spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads. spacewalk-backend de Red Hat Network Satellite 5.4 de Red Hat Enterprise Linux 6 no autoriza ni autentica apropiadamente las subidas a la organización NULL si mod_wsgi es utilizado... • http://rhn.redhat.com/errata/RHSA-2012-0436.html • CWE-287: Improper Authentication •

CVE-2011-3544 – Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2011-3544
19 Oct 2011 — Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting. Vulnerabilidad no especificada en el componente de Java Runtime Environment en Oracle Java SE JDK y JRE v7 y v6 Update 27 y anteriores permite a aplicaciones remotas Java Web Start y applets Java no confiable... • https://www.exploit-db.com/exploits/18171 • CWE-284: Improper Access Control •

CVE-2010-1171 – rhn_satellite: Improper channel comps information management
https://notcve.org/view.php?id=CVE-2010-1171
18 Apr 2011 — Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels. Vulnerabilidad de redirección abierta en el obsoleto API de XML-RPC en Red Hat Network (RHN) Satellite v5.3 y v5.4, que permite a usuarios remotos autenticados acceder a archivos arbitrarios y causar una denegación de ... • http://secunia.com/advisories/44150 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2009-0788 – rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
https://notcve.org/view.php?id=CVE-2009-0788
18 Apr 2011 — Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors. Red Hat Network (RHN) Satellite Server 5.3 y 5.4 no reescribe correctamente URLs no especificadas, lo que permite a atacantes remotos (1) obtener información sensible no especificado del anfitrión o (2) utilizar e... • http://secunia.com/advisories/44150 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2011-0717 – Spacewalk: Session fixation flaw
https://notcve.org/view.php?id=CVE-2011-0717
25 Feb 2011 — Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk. Vulnerabilidad de fijación de sesión en Red Hat Network (RHN) Satellite Server v5.4 permite a atacantes remotos secuestrar sesiones web a través de vectores no especificados relacionados con Spacewalk • http://secunia.com/advisories/43487 • CWE-384: Session Fixation •

CVE-2011-0718 – Spacewalk: Prone to brute force password guessing attacks
https://notcve.org/view.php?id=CVE-2011-0718
25 Feb 2011 — Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks. Red Hat Network (RHN) Satellite Server v5.4 no utiliza un intervalo de tiempo después de un intento de login fallido, lo que facilita a los atacantes remotos realizar ataques de contraseña por fuerza bruta. • http://secunia.com/advisories/43487 • CWE-287: Improper Authentication •