CVE-2014-3654
Satellite: Spacewalk contains multiple XSS (stored and reflected)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3) admin/multiorg/OrgUsers.do.
MĂșltiples vulnerabilidades de XSS en spacewalk-java 2.0.2 en Spacewalk and Red Hat Network (RHN) Satellite 5.5 y 5.6 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a travĂ©s de vectores no especificados en (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, o (3) admin/multiorg/OrgUsers.do.
Stored and reflected cross-site scripting (XSS) flaws were found in the way spacewalk-java displayed certain information. By sending a specially crafted request to Satellite, a remote, authenticated attacker could embed HTML content into the stored data, allowing them to inject malicious content into the web page that is used to view that data.
Red Hat Satellite is a systems management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and remote management of multiple Linux deployments with a single, centralized tool. The spacewalk-java packages contain the code for the Java version of the Spacewalk Web site. Stored and reflected cross-site scripting flaws were found in the way spacewalk-java displayed certain information. By sending a specially crafted request to Satellite, a remote, authenticated attacker could embed HTML content into the stored data, allowing them to inject malicious content into the web page that is used to view that data.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-10-30 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/60976 | Third Party Advisory | |
http://secunia.com/advisories/62027 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00009.html | 2023-02-13 | |
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00010.html | 2023-02-13 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-1762.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2014-3654 | 2014-10-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1144628 | 2014-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Suse Search vendor "Suse" | Manager Search vendor "Suse" for product "Manager" | 1.7 Search vendor "Suse" for product "Manager" and version "1.7" | - |
Affected
| in | Suse Search vendor "Suse" | Suse Linux Enterprise Server Search vendor "Suse" for product "Suse Linux Enterprise Server" | 11 Search vendor "Suse" for product "Suse Linux Enterprise Server" and version "11" | sp2 |
Safe
|
Redhat Search vendor "Redhat" | Satellite Search vendor "Redhat" for product "Satellite" | 5.5 Search vendor "Redhat" for product "Satellite" and version "5.5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Satellite Search vendor "Redhat" for product "Satellite" | 5.6 Search vendor "Redhat" for product "Satellite" and version "5.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Satellite With Embedded Oracle Search vendor "Redhat" for product "Satellite With Embedded Oracle" | 5.5 Search vendor "Redhat" for product "Satellite With Embedded Oracle" and version "5.5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Spacewalk-java Search vendor "Redhat" for product "Spacewalk-java" | 2.0.2 Search vendor "Redhat" for product "Spacewalk-java" and version "2.0.2" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Manager Server Search vendor "Suse" for product "Manager Server" | - | - |
Affected
|