CVE-2012-6149
(spacewalk-java): XSS in system.addNote XML-RPC call due improper sanitization of note's subject and content
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.
MĂșltiples vulnerabilidades de XSS en systems/sdc/notes.jsp en Spacewalk y Red Hat Network (RHN) Satellite 5.6 permiten a atacantes remotos inyectar script Web o HTML arbitrarios a travĂ©s de los valores de (1) asunto o (2) contenido de una nota en una llamada XML-RPC a system.addNote.
Red Hat Satellite is a systems management tool for Linux-based infrastructures. It allows for provisioning, remote management and monitoring of multiple Linux deployments with a single, centralized tool. A cross-site scripting flaw was found in the way the Red Hat Satellite web interface performed sanitization of notes for registered systems. A remote authenticated Red Hat Satellite user could create a malicious note that, when viewed by a victim, could execute arbitrary web script with the privileges of the user viewing that note. Multiple cross-site scripting flaws were found in the Red Hat Satellite web interface. A remote attacker could provide a specially crafted link that, when visited by an authenticated Red Hat Satellite user, would lead to arbitrary web script execution in the context of the user's web interface session.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-12-06 CVE Reserved
- 2014-02-10 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/56952 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=1d0f4b4a78ea03d9f2d05fbd52236b1f2ab68e85 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ac55c6656bb19b3b13f | 2022-02-25 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-0148.html | 2022-02-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=882000 | 2014-02-10 | |
https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html | 2022-02-25 | |
https://access.redhat.com/security/cve/CVE-2012-6149 | 2014-02-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Satellite Search vendor "Redhat" for product "Satellite" | 5.6 Search vendor "Redhat" for product "Satellite" and version "5.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Satellite 5 Managed Db Search vendor "Redhat" for product "Satellite 5 Managed Db" | 5.6 Search vendor "Redhat" for product "Satellite 5 Managed Db" and version "5.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Spacewalk-java Search vendor "Redhat" for product "Spacewalk-java" | 2.0.2-57 Search vendor "Redhat" for product "Spacewalk-java" and version "2.0.2-57" | - |
Affected
|