Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2015-0284 (GCVE-0-2015-0284)
Vulnerability from cvelistv5
Published
2016-04-14 14:00
Modified
2024-08-06 04:03
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T04:03:10.886Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "RHSA-2016:0590", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-0590.html" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2016-04-04T00:00:00", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2016-04-14T13:57:01", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat" }, "references": [ { "name": "RHSA-2016:0590", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-0590.html" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794" } ] } }, "cveMetadata": { "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2015-0284", "datePublished": "2016-04-14T14:00:00", "dateReserved": "2014-11-18T00:00:00", "dateUpdated": "2024-08-06T04:03:10.886Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2015-0284\",\"sourceIdentifier\":\"secalert@redhat.com\",\"published\":\"2016-04-14T14:59:00.147\",\"lastModified\":\"2025-04-12T10:46:40.837\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.\"},{\"lang\":\"es\",\"value\":\"Vulnerabilidad de XSS en spacewalk-java en Spacewalk y Red Hat Satellite 5.7 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s de datos XML manipulados en la API XMLRPC, involucrando detalles de usuario. NOTA: esta vulnerabilidad existe debido a una soluci\u00f3n incompleta para CVE-2014-7811.\"}],\"metrics\":{\"cvssMetricV30\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.0\",\"vectorString\":\"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N\",\"baseScore\":5.4,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"LOW\",\"userInteraction\":\"REQUIRED\",\"scope\":\"CHANGED\",\"confidentialityImpact\":\"LOW\",\"integrityImpact\":\"LOW\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":2.3,\"impactScore\":2.7}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:M/Au:S/C:N/I:P/A:N\",\"baseScore\":3.5,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"MEDIUM\",\"authentication\":\"SINGLE\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"LOW\",\"exploitabilityScore\":6.8,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-79\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"85EA16E0-9261-45C4-840F-5366E9EAC5E1\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:redhat:spacewalk-java:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"BB6F3D1C-DDF1-49B6-8E4D-38B037F33030\"}]}]}],\"references\":[{\"url\":\"http://rhn.redhat.com/errata/RHSA-2016-0590.html\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1181152\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1181472\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1314906\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1315398\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://rhn.redhat.com/errata/RHSA-2016-0590.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1181152\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1181472\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1314906\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1315398\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"}]}}" } }
gsd-2015-0284
Vulnerability from gsd
Modified
2023-12-13 01:19
Details
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2015-0284", "description": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.", "id": "GSD-2015-0284", "references": [ "https://www.suse.com/security/cve/CVE-2015-0284.html", "https://access.redhat.com/errata/RHSA-2016:0590" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2015-0284" ], "details": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.", "id": "GSD-2015-0284", "modified": "2023-12-13T01:19:58.106821Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2015-0284", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_affected": "=", "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "http://rhn.redhat.com/errata/RHSA-2016-0590.html", "refsource": "MISC", "url": "http://rhn.redhat.com/errata/RHSA-2016-0590.html" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152", "refsource": "MISC", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906", "refsource": "MISC", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398", "refsource": "MISC", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398" }, { "name": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744", "refsource": "MISC", "url": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744" }, { "name": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794", "refsource": "MISC", "url": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472", "refsource": "MISC", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:redhat:spacewalk-java:-:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2015-0284" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-79" } ] } ] }, "references": { "reference_data": [ { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906", "refsource": "CONFIRM", "tags": [], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906" }, { "name": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744", "refsource": "CONFIRM", "tags": [], "url": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398", "refsource": "CONFIRM", "tags": [], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398" }, { "name": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794", "refsource": "CONFIRM", "tags": [], "url": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794" }, { "name": "RHSA-2016:0590", "refsource": "REDHAT", "tags": [ "Vendor Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-0590.html" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152", "refsource": "CONFIRM", "tags": [], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472", "refsource": "CONFIRM", "tags": [], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" } ] } }, "impact": { "baseMetricV2": { "acInsufInfo": false, "cvssV2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 3.5, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 6.8, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "LOW", "userInteractionRequired": false }, "baseMetricV3": { "cvssV3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "version": "3.0" }, "exploitabilityScore": 2.3, "impactScore": 2.7 } }, "lastModifiedDate": "2023-02-13T00:46Z", "publishedDate": "2016-04-14T14:59Z" } } }
suse-su-2016:1367-1
Vulnerability from csaf_suse
Published
2016-05-19 20:37
Modified
2016-05-19 20:37
Summary
Security update for SUSE Manager Server 2.1
Notes
Title of the patch
Security update for SUSE Manager Server 2.1
Description of the patch
This update for SUSE Manager Server 2.1 fixes the following issues:
cobbler:
- Add logrotate file for cobbler (bsc#976826)
- Fix cobbler yaboot handling (bsc#968406, bsc#966622)
osad:
- Fix file permissions (bsc#970550)
rhnlib:
- Use TLSv1_METHOD in SSL Context (bsc#970989)
spacewalk-backend:
- Mgr_ncc_sync: Adapt to bulk scheduling introduced in scheduleSingleSatRepoSync
spacewalk-branding:
- Fix link to 'Schedule patch updates' (bsc#973432)
- Fix link to scheduled action for SP migration (bsc#968257, bsc#974315)
- Fix: 'Advanced Search' title consistency
spacewalk-certs-tools:
- Fix file permissions (bsc#970550)
spacewalk-java:
- Recreate upgrade paths on every refresh (bsc#978166)
- Call cobbler sync after cobbler command is finished (bsc#966890)
- Under high load, the service wrapper may incorrectly interpret the inability
to get a response in time from taskomatic and kill it (bsc#962253)
- Log permissions problems on channel access while SP migration (bsc#970223)
- Unittests: support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194)
- Mgr-sync: use bulk channel reposync (bsc#961002)
- Double the backslashes when reading the config files from java (bsc#958923)
- When generating repo metadata for a cloned channel, recursively fetch
keywords from the original channel (bsc#970901)
- Better logging for SP Migration feature (bsc#970223)
- Fix: 'Advanced Search' title consistency
- CVE-2015-0284: XSS when altering user details and going somewhere where you are
choosing user (bsc#922740)
- CVE-2016-3079, CVE-2016-2103, CVE-2016-2104, CVE-2016-3097: Fix multiple XSS
vulnerabilities (bsc#973162, bsc#974011, bsc#974010, bsc#973550)
- BugFix: 'Systems > Advanced Search' title and description consistency
(bsc#966737)
- Fix: correct behavior with visibility conditions of sub-tabs in Systems/Misc
page
- BugFix: add missing url mapping (bsc#961565)
- Fix kernel and initrd pathes for creating autoinstallation tries (bsc#966622)
- Fix tests for HAE-GEO on SLES 4 SAP (bsc#970425)
- Add unit tests for SLE-Live-Patching12 (bsc#924298)
spacewalk-utils:
- Bugfix: don't repeat channel labels
- Taskotop: a utility to monitor what Taskomatic is doing
- Fix file permissions (bsc#970550)
suseRegisterInfo:
- Fix file permissions (bsc#970550)
susemanager:
- Add packages to bootstrap repo (bsc#971237)
- Mgr-sync: use bulk channel reposync (bsc#961002)
- Mgr_ncc_sync: adapt to bulk scheduling introduced in
scheduleSingleSatRepoSync
- Add SLES 4 SAP to mgr-create-bootstap-repo as an option (bsc#972341)
- Put packages only available in SLE12 SP1 in a seperate list (bsc#970672)
- Fix file permissions (bsc#970550)
susemanager-sync-data:
- Support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194)
- HAE-GEO is an addon product for SLES 4 SAP (bsc#970425)
- Add support for SLE-Live-Patching12 (bsc#924298, bsc#968851)
susemanager-tftpsync:
- Rename change_tftpd_proxies.py to sync_post_tftpd_proxies.py and change
trigger type (bsc#966890)
How to apply this update:
1. Log in as root user to the SUSE Manager server.
2. Stop the Spacewalk service:
spacewalk-service stop
3. Apply the patch using either zypper patch or YaST Online Update.
4. Start the Spacewalk service:
spacewalk-service start
Patchnames
sleman21-suse-manager-21-201605-12567
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for SUSE Manager Server 2.1", "title": "Title of the patch" }, { "category": "description", "text": "\nThis update for SUSE Manager Server 2.1 fixes the following issues:\n\ncobbler:\n\n- Add logrotate file for cobbler (bsc#976826)\n- Fix cobbler yaboot handling (bsc#968406, bsc#966622)\n\nosad:\n\n- Fix file permissions (bsc#970550)\n\nrhnlib:\n\n- Use TLSv1_METHOD in SSL Context (bsc#970989)\n\nspacewalk-backend:\n\n- Mgr_ncc_sync: Adapt to bulk scheduling introduced in scheduleSingleSatRepoSync\n\nspacewalk-branding:\n\n- Fix link to \u0027Schedule patch updates\u0027 (bsc#973432)\n- Fix link to scheduled action for SP migration (bsc#968257, bsc#974315)\n- Fix: \u0027Advanced Search\u0027 title consistency\n\nspacewalk-certs-tools:\n\n- Fix file permissions (bsc#970550)\n\nspacewalk-java:\n\n- Recreate upgrade paths on every refresh (bsc#978166)\n- Call cobbler sync after cobbler command is finished (bsc#966890)\n- Under high load, the service wrapper may incorrectly interpret the inability\n to get a response in time from taskomatic and kill it (bsc#962253)\n- Log permissions problems on channel access while SP migration (bsc#970223)\n- Unittests: support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194)\n- Mgr-sync: use bulk channel reposync (bsc#961002)\n- Double the backslashes when reading the config files from java (bsc#958923)\n- When generating repo metadata for a cloned channel, recursively fetch\n keywords from the original channel (bsc#970901)\n- Better logging for SP Migration feature (bsc#970223)\n- Fix: \u0027Advanced Search\u0027 title consistency\n- CVE-2015-0284: XSS when altering user details and going somewhere where you are\n choosing user (bsc#922740)\n- CVE-2016-3079, CVE-2016-2103, CVE-2016-2104, CVE-2016-3097: Fix multiple XSS\n vulnerabilities (bsc#973162, bsc#974011, bsc#974010, bsc#973550)\n- BugFix: \u0027Systems \u003e Advanced Search\u0027 title and description consistency\n (bsc#966737)\n- Fix: correct behavior with visibility conditions of sub-tabs in Systems/Misc\n page\n- BugFix: add missing url mapping (bsc#961565)\n- Fix kernel and initrd pathes for creating autoinstallation tries (bsc#966622)\n- Fix tests for HAE-GEO on SLES 4 SAP (bsc#970425)\n- Add unit tests for SLE-Live-Patching12 (bsc#924298)\n\nspacewalk-utils:\n\n- Bugfix: don\u0027t repeat channel labels\n- Taskotop: a utility to monitor what Taskomatic is doing\n- Fix file permissions (bsc#970550)\n\nsuseRegisterInfo:\n\n- Fix file permissions (bsc#970550)\n\nsusemanager:\n\n- Add packages to bootstrap repo (bsc#971237)\n- Mgr-sync: use bulk channel reposync (bsc#961002)\n- Mgr_ncc_sync: adapt to bulk scheduling introduced in\n scheduleSingleSatRepoSync\n- Add SLES 4 SAP to mgr-create-bootstap-repo as an option (bsc#972341)\n- Put packages only available in SLE12 SP1 in a seperate list (bsc#970672)\n- Fix file permissions (bsc#970550)\n\nsusemanager-sync-data:\n\n- Support SLE-POS 11 SP3 as addon for SLES 11 SP4 (bsc#976194)\n- HAE-GEO is an addon product for SLES 4 SAP (bsc#970425)\n- Add support for SLE-Live-Patching12 (bsc#924298, bsc#968851)\n\nsusemanager-tftpsync:\n\n- Rename change_tftpd_proxies.py to sync_post_tftpd_proxies.py and change\n trigger type (bsc#966890)\n\nHow to apply this update:\n1. Log in as root user to the SUSE Manager server.\n2. Stop the Spacewalk service:\nspacewalk-service stop\n3. Apply the patch using either zypper patch or YaST Online Update.\n4. Start the Spacewalk service:\nspacewalk-service start\n", "title": "Description of the patch" }, { "category": "details", "text": "sleman21-suse-manager-21-201605-12567", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2016_1367-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2016:1367-1", "url": "https://www.suse.com/support/update/announcement/2016/suse-su-20161367-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2016:1367-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2016-May/002076.html" }, { "category": "self", "summary": "SUSE Bug 922740", "url": "https://bugzilla.suse.com/922740" }, { "category": "self", "summary": "SUSE Bug 924298", "url": "https://bugzilla.suse.com/924298" }, { "category": "self", "summary": "SUSE Bug 958923", "url": "https://bugzilla.suse.com/958923" }, { "category": "self", "summary": "SUSE Bug 961002", "url": "https://bugzilla.suse.com/961002" }, { "category": "self", "summary": "SUSE Bug 961565", "url": "https://bugzilla.suse.com/961565" }, { "category": "self", "summary": "SUSE Bug 962253", "url": "https://bugzilla.suse.com/962253" }, { "category": "self", "summary": "SUSE Bug 966622", "url": "https://bugzilla.suse.com/966622" }, { "category": "self", "summary": "SUSE Bug 966737", "url": "https://bugzilla.suse.com/966737" }, { "category": "self", "summary": "SUSE Bug 966890", "url": "https://bugzilla.suse.com/966890" }, { "category": "self", "summary": "SUSE Bug 968257", "url": "https://bugzilla.suse.com/968257" }, { "category": "self", "summary": "SUSE Bug 968406", "url": "https://bugzilla.suse.com/968406" }, { "category": "self", "summary": "SUSE Bug 968851", "url": "https://bugzilla.suse.com/968851" }, { "category": "self", "summary": "SUSE Bug 970223", "url": "https://bugzilla.suse.com/970223" }, { "category": "self", "summary": "SUSE Bug 970425", "url": "https://bugzilla.suse.com/970425" }, { "category": "self", "summary": "SUSE Bug 970550", "url": "https://bugzilla.suse.com/970550" }, { "category": "self", "summary": "SUSE Bug 970672", "url": "https://bugzilla.suse.com/970672" }, { "category": "self", "summary": "SUSE Bug 970901", "url": "https://bugzilla.suse.com/970901" }, { "category": "self", "summary": "SUSE Bug 970989", "url": "https://bugzilla.suse.com/970989" }, { "category": "self", "summary": "SUSE Bug 971237", "url": "https://bugzilla.suse.com/971237" }, { "category": "self", "summary": "SUSE Bug 972341", "url": "https://bugzilla.suse.com/972341" }, { "category": "self", "summary": "SUSE Bug 973162", "url": "https://bugzilla.suse.com/973162" }, { "category": "self", "summary": "SUSE Bug 973432", "url": "https://bugzilla.suse.com/973432" }, { "category": "self", "summary": "SUSE Bug 973550", "url": "https://bugzilla.suse.com/973550" }, { "category": "self", "summary": "SUSE Bug 974010", "url": "https://bugzilla.suse.com/974010" }, { "category": "self", "summary": "SUSE Bug 974011", "url": "https://bugzilla.suse.com/974011" }, { "category": "self", "summary": "SUSE Bug 974315", "url": "https://bugzilla.suse.com/974315" }, { "category": "self", "summary": "SUSE Bug 976194", "url": "https://bugzilla.suse.com/976194" }, { "category": "self", "summary": "SUSE Bug 976826", "url": "https://bugzilla.suse.com/976826" }, { "category": "self", "summary": "SUSE Bug 978166", "url": "https://bugzilla.suse.com/978166" }, { "category": "self", "summary": "SUSE CVE CVE-2015-0284 page", "url": "https://www.suse.com/security/cve/CVE-2015-0284/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2103 page", "url": "https://www.suse.com/security/cve/CVE-2016-2103/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2104 page", "url": "https://www.suse.com/security/cve/CVE-2016-2104/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-3079 page", "url": "https://www.suse.com/security/cve/CVE-2016-3079/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-3097 page", "url": "https://www.suse.com/security/cve/CVE-2016-3097/" } ], "title": "Security update for SUSE Manager Server 2.1", "tracking": { "current_release_date": "2016-05-19T20:37:06Z", "generator": { "date": "2016-05-19T20:37:06Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2016:1367-1", "initial_release_date": "2016-05-19T20:37:06Z", "revision_history": [ { "date": "2016-05-19T20:37:06Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "osa-dispatcher-5.11.33.11-15.2.noarch", "product": { "name": "osa-dispatcher-5.11.33.11-15.2.noarch", "product_id": "osa-dispatcher-5.11.33.11-15.2.noarch" } }, { "category": "product_version", "name": "spacewalk-certs-tools-2.1.6.10-18.3.noarch", "product": { "name": "spacewalk-certs-tools-2.1.6.10-18.3.noarch", "product_id": "spacewalk-certs-tools-2.1.6.10-18.3.noarch" } }, { "category": "product_version", "name": "spacewalk-java-2.1.165.23-20.1.noarch", "product": { "name": "spacewalk-java-2.1.165.23-20.1.noarch", "product_id": "spacewalk-java-2.1.165.23-20.1.noarch" } }, { "category": "product_version", "name": "spacewalk-java-config-2.1.165.23-20.1.noarch", "product": { "name": "spacewalk-java-config-2.1.165.23-20.1.noarch", "product_id": "spacewalk-java-config-2.1.165.23-20.1.noarch" } }, { "category": "product_version", "name": "spacewalk-java-lib-2.1.165.23-20.1.noarch", "product": { "name": "spacewalk-java-lib-2.1.165.23-20.1.noarch", "product_id": "spacewalk-java-lib-2.1.165.23-20.1.noarch" } }, { "category": "product_version", "name": "spacewalk-java-oracle-2.1.165.23-20.1.noarch", "product": { "name": "spacewalk-java-oracle-2.1.165.23-20.1.noarch", "product_id": "spacewalk-java-oracle-2.1.165.23-20.1.noarch" } }, { "category": "product_version", "name": "spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "product": { "name": "spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "product_id": "spacewalk-java-postgresql-2.1.165.23-20.1.noarch" } }, { "category": "product_version", "name": "spacewalk-taskomatic-2.1.165.23-20.1.noarch", "product": { "name": "spacewalk-taskomatic-2.1.165.23-20.1.noarch", "product_id": "spacewalk-taskomatic-2.1.165.23-20.1.noarch" } }, { "category": "product_version", "name": "spacewalk-utils-2.1.27.15-12.7.noarch", "product": { "name": "spacewalk-utils-2.1.27.15-12.7.noarch", "product_id": "spacewalk-utils-2.1.27.15-12.7.noarch" } }, { "category": "product_version", "name": "susemanager-sync-data-2.1.15-30.2.noarch", "product": { "name": "susemanager-sync-data-2.1.15-30.2.noarch", "product_id": "susemanager-sync-data-2.1.15-30.2.noarch" } } ], "category": "architecture", "name": "noarch" }, { "branches": [ { "category": "product_version", "name": "cobbler-2.2.2-0.61.2.s390x", "product": { "name": "cobbler-2.2.2-0.61.2.s390x", "product_id": "cobbler-2.2.2-0.61.2.s390x" } }, { "category": "product_version", "name": "rhnlib-2.5.69.8-11.2.s390x", "product": { "name": "rhnlib-2.5.69.8-11.2.s390x", "product_id": "rhnlib-2.5.69.8-11.2.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-app-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-app-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-app-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-applet-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-applet-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-applet-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-config-files-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-iss-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-iss-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-iss-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-iss-export-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-libs-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-libs-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-libs-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-server-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-server-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-server-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-sql-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-sql-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-sql-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-tools-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-tools-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-tools-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "product": { "name": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "product_id": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x" } }, { "category": "product_version", "name": "spacewalk-branding-2.1.33.16-18.2.s390x", "product": { "name": "spacewalk-branding-2.1.33.16-18.2.s390x", "product_id": "spacewalk-branding-2.1.33.16-18.2.s390x" } }, { "category": "product_version", "name": "suseRegisterInfo-2.1.12-14.2.s390x", "product": { "name": "suseRegisterInfo-2.1.12-14.2.s390x", "product_id": "suseRegisterInfo-2.1.12-14.2.s390x" } }, { "category": "product_version", "name": "susemanager-2.1.24-23.1.s390x", "product": { "name": "susemanager-2.1.24-23.1.s390x", "product_id": "susemanager-2.1.24-23.1.s390x" } }, { "category": "product_version", "name": "susemanager-tftpsync-2.1.2-11.2.s390x", "product": { "name": "susemanager-tftpsync-2.1.2-11.2.s390x", "product_id": "susemanager-tftpsync-2.1.2-11.2.s390x" } }, { "category": "product_version", "name": "susemanager-tools-2.1.24-23.1.s390x", "product": { "name": "susemanager-tools-2.1.24-23.1.s390x", "product_id": "susemanager-tools-2.1.24-23.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "cobbler-2.2.2-0.61.2.x86_64", "product": { "name": "cobbler-2.2.2-0.61.2.x86_64", "product_id": "cobbler-2.2.2-0.61.2.x86_64" } }, { "category": "product_version", "name": "rhnlib-2.5.69.8-11.2.x86_64", "product": { "name": "rhnlib-2.5.69.8-11.2.x86_64", "product_id": "rhnlib-2.5.69.8-11.2.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-app-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-app-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-app-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-applet-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-config-files-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-iss-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-libs-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-server-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-server-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-server-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-sql-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-tools-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "product": { "name": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "product_id": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64" } }, { "category": "product_version", "name": "spacewalk-branding-2.1.33.16-18.2.x86_64", "product": { "name": "spacewalk-branding-2.1.33.16-18.2.x86_64", "product_id": "spacewalk-branding-2.1.33.16-18.2.x86_64" } }, { "category": "product_version", "name": "suseRegisterInfo-2.1.12-14.2.x86_64", "product": { "name": "suseRegisterInfo-2.1.12-14.2.x86_64", "product_id": "suseRegisterInfo-2.1.12-14.2.x86_64" } }, { "category": "product_version", "name": "susemanager-2.1.24-23.1.x86_64", "product": { "name": "susemanager-2.1.24-23.1.x86_64", "product_id": "susemanager-2.1.24-23.1.x86_64" } }, { "category": "product_version", "name": "susemanager-tftpsync-2.1.2-11.2.x86_64", "product": { "name": "susemanager-tftpsync-2.1.2-11.2.x86_64", "product_id": "susemanager-tftpsync-2.1.2-11.2.x86_64" } }, { "category": "product_version", "name": "susemanager-tools-2.1.24-23.1.x86_64", "product": { "name": "susemanager-tools-2.1.24-23.1.x86_64", "product_id": "susemanager-tools-2.1.24-23.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Manager 2.1", "product": { "name": "SUSE Manager 2.1", "product_id": "SUSE Manager 2.1", "product_identification_helper": { "cpe": "cpe:/o:suse:suse-manager-server:2.1" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "cobbler-2.2.2-0.61.2.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x" }, "product_reference": "cobbler-2.2.2-0.61.2.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "cobbler-2.2.2-0.61.2.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64" }, "product_reference": "cobbler-2.2.2-0.61.2.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "osa-dispatcher-5.11.33.11-15.2.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch" }, "product_reference": "osa-dispatcher-5.11.33.11-15.2.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "rhnlib-2.5.69.8-11.2.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x" }, "product_reference": "rhnlib-2.5.69.8-11.2.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "rhnlib-2.5.69.8-11.2.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64" }, "product_reference": "rhnlib-2.5.69.8-11.2.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-app-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-app-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-app-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-app-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-applet-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-applet-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-applet-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-config-files-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-config-files-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-iss-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-iss-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-iss-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-iss-export-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-libs-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-libs-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-libs-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-server-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-server-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-server-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-server-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-sql-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-sql-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-sql-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-tools-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-tools-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-tools-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x" }, "product_reference": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64" }, "product_reference": "spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-branding-2.1.33.16-18.2.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x" }, "product_reference": "spacewalk-branding-2.1.33.16-18.2.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-branding-2.1.33.16-18.2.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64" }, "product_reference": "spacewalk-branding-2.1.33.16-18.2.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-certs-tools-2.1.6.10-18.3.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch" }, "product_reference": "spacewalk-certs-tools-2.1.6.10-18.3.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-2.1.165.23-20.1.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch" }, "product_reference": "spacewalk-java-2.1.165.23-20.1.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-config-2.1.165.23-20.1.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch" }, "product_reference": "spacewalk-java-config-2.1.165.23-20.1.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-lib-2.1.165.23-20.1.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch" }, "product_reference": "spacewalk-java-lib-2.1.165.23-20.1.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-oracle-2.1.165.23-20.1.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch" }, "product_reference": "spacewalk-java-oracle-2.1.165.23-20.1.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-postgresql-2.1.165.23-20.1.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch" }, "product_reference": "spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-taskomatic-2.1.165.23-20.1.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch" }, "product_reference": "spacewalk-taskomatic-2.1.165.23-20.1.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-utils-2.1.27.15-12.7.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch" }, "product_reference": "spacewalk-utils-2.1.27.15-12.7.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "suseRegisterInfo-2.1.12-14.2.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x" }, "product_reference": "suseRegisterInfo-2.1.12-14.2.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "suseRegisterInfo-2.1.12-14.2.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64" }, "product_reference": "suseRegisterInfo-2.1.12-14.2.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "susemanager-2.1.24-23.1.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x" }, "product_reference": "susemanager-2.1.24-23.1.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "susemanager-2.1.24-23.1.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64" }, "product_reference": "susemanager-2.1.24-23.1.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "susemanager-sync-data-2.1.15-30.2.noarch as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch" }, "product_reference": "susemanager-sync-data-2.1.15-30.2.noarch", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "susemanager-tftpsync-2.1.2-11.2.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x" }, "product_reference": "susemanager-tftpsync-2.1.2-11.2.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "susemanager-tftpsync-2.1.2-11.2.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64" }, "product_reference": "susemanager-tftpsync-2.1.2-11.2.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "susemanager-tools-2.1.24-23.1.s390x as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x" }, "product_reference": "susemanager-tools-2.1.24-23.1.s390x", "relates_to_product_reference": "SUSE Manager 2.1" }, { "category": "default_component_of", "full_product_name": { "name": "susemanager-tools-2.1.24-23.1.x86_64 as component of SUSE Manager 2.1", "product_id": "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" }, "product_reference": "susemanager-tools-2.1.24-23.1.x86_64", "relates_to_product_reference": "SUSE Manager 2.1" } ] }, "vulnerabilities": [ { "cve": "CVE-2015-0284", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2015-0284" } ], "notes": [ { "category": "general", "text": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2015-0284", "url": "https://www.suse.com/security/cve/CVE-2015-0284" }, { "category": "external", "summary": "SUSE Bug 902915 for CVE-2015-0284", "url": "https://bugzilla.suse.com/902915" }, { "category": "external", "summary": "SUSE Bug 922740 for CVE-2015-0284", "url": "https://bugzilla.suse.com/922740" }, { "category": "external", "summary": "SUSE Bug 969911 for CVE-2015-0284", "url": "https://bugzilla.suse.com/969911" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "version": "3.0" }, "products": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-05-19T20:37:06Z", "details": "moderate" } ], "title": "CVE-2015-0284" }, { "cve": "CVE-2016-2103", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2103" } ], "notes": [ { "category": "general", "text": "Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2103", "url": "https://www.suse.com/security/cve/CVE-2016-2103" }, { "category": "external", "summary": "SUSE Bug 974011 for CVE-2016-2103", "url": "https://bugzilla.suse.com/974011" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "version": "3.0" }, "products": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-05-19T20:37:06Z", "details": "moderate" } ], "title": "CVE-2016-2103" }, { "cve": "CVE-2016-2104", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2104" } ], "notes": [ { "category": "general", "text": "Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the package_name, (3) search_subscribed_channels, or (4) channel_filter parameter to software/packages/NameOverview.do; or unspecified vectors related to (5) \u003cinput:hidden\u003e or (6) \u003cbean:message\u003e tags.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2104", "url": "https://www.suse.com/security/cve/CVE-2016-2104" }, { "category": "external", "summary": "SUSE Bug 974010 for CVE-2016-2104", "url": "https://bugzilla.suse.com/974010" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "version": "3.0" }, "products": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-05-19T20:37:06Z", "details": "moderate" } ], "title": "CVE-2016-2104" }, { "cve": "CVE-2016-3079", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-3079" } ], "notes": [ { "category": "general", "text": "Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-3079", "url": "https://www.suse.com/security/cve/CVE-2016-3079" }, { "category": "external", "summary": "SUSE Bug 973162 for CVE-2016-3079", "url": "https://bugzilla.suse.com/973162" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "version": "3.0" }, "products": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-05-19T20:37:06Z", "details": "moderate" } ], "title": "CVE-2016-3079" }, { "cve": "CVE-2016-3097", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-3097" } ], "notes": [ { "category": "general", "text": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-3097", "url": "https://www.suse.com/security/cve/CVE-2016-3097" }, { "category": "external", "summary": "SUSE Bug 973550 for CVE-2016-3097", "url": "https://bugzilla.suse.com/973550" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "version": "3.0" }, "products": [ "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.s390x", "SUSE Manager 2.1:cobbler-2.2.2-0.61.2.x86_64", "SUSE Manager 2.1:osa-dispatcher-5.11.33.11-15.2.noarch", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.s390x", "SUSE Manager 2.1:rhnlib-2.5.69.8-11.2.x86_64", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-app-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-applet-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-common-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-config-files-tool-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-iss-export-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-package-push-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-server-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-oracle-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-sql-postgresql-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-tools-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xml-export-libs-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.s390x", "SUSE Manager 2.1:spacewalk-backend-xmlrpc-2.1.55.25-24.5.x86_64", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.s390x", "SUSE Manager 2.1:spacewalk-branding-2.1.33.16-18.2.x86_64", "SUSE Manager 2.1:spacewalk-certs-tools-2.1.6.10-18.3.noarch", "SUSE Manager 2.1:spacewalk-java-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-config-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-lib-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-oracle-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-java-postgresql-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-taskomatic-2.1.165.23-20.1.noarch", "SUSE Manager 2.1:spacewalk-utils-2.1.27.15-12.7.noarch", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.s390x", "SUSE Manager 2.1:suseRegisterInfo-2.1.12-14.2.x86_64", "SUSE Manager 2.1:susemanager-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-2.1.24-23.1.x86_64", "SUSE Manager 2.1:susemanager-sync-data-2.1.15-30.2.noarch", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.s390x", "SUSE Manager 2.1:susemanager-tftpsync-2.1.2-11.2.x86_64", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.s390x", "SUSE Manager 2.1:susemanager-tools-2.1.24-23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-05-19T20:37:06Z", "details": "moderate" } ], "title": "CVE-2016-3097" } ] }
rhsa-2016:0590
Vulnerability from csaf_redhat
Published
2016-04-04 15:35
Modified
2024-11-22 09:57
Summary
Red Hat Security Advisory: spacewalk-java security update
Notes
Topic
An update for spacewalk-java is now available for Red Hat Satellite 5.7.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Details
Red Hat Satellite is a system management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and the remote management of multiple Linux deployments with a single, centralized tool.
Security Fix(es):
* A cross-site scripting (XSS) flaw was found in how XML data was handled in Red Hat Satellite. A user able to use the XMLRPC API could exploit this flaw to perform XSS attacks against other Satellite users. (CVE-2015-0284)
* Multiple cross-site scripting (XSS) flaws were found in the way certain form data was handled in Red Hat Satellite. A user able to enter form data could use these flaws to perform XSS attacks against other Satellite users. (CVE-2016-2103, CVE-2016-3079)
* Multiple cross-site scripting (XSS) flaws were found in the way HTTP GET parameter data was handled in Red Hat Satellite. A user able to provide malicious links to a Satellite user could use these flaws to perform XSS attacks against other Satellite users. (CVE-2016-2104)
Red Hat would like to thank Adam Willard (Raytheon Foreground Security) for reporting CVE-2016-2104. The CVE-2015-0284 and CVE-2016-3079 issues were discovered by Jan Hutař (Red Hat).
Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "An update for spacewalk-java is now available for Red Hat Satellite 5.7.\n\nRed Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.", "title": "Topic" }, { "category": "general", "text": "Red Hat Satellite is a system management tool for Linux-based infrastructures. It allows for provisioning, monitoring, and the remote management of multiple Linux deployments with a single, centralized tool.\n\nSecurity Fix(es):\n\n* A cross-site scripting (XSS) flaw was found in how XML data was handled in Red Hat Satellite. A user able to use the XMLRPC API could exploit this flaw to perform XSS attacks against other Satellite users. (CVE-2015-0284)\n\n* Multiple cross-site scripting (XSS) flaws were found in the way certain form data was handled in Red Hat Satellite. A user able to enter form data could use these flaws to perform XSS attacks against other Satellite users. (CVE-2016-2103, CVE-2016-3079)\n\n* Multiple cross-site scripting (XSS) flaws were found in the way HTTP GET parameter data was handled in Red Hat Satellite. A user able to provide malicious links to a Satellite user could use these flaws to perform XSS attacks against other Satellite users. (CVE-2016-2104)\n\nRed Hat would like to thank Adam Willard (Raytheon Foreground Security) for reporting CVE-2016-2104. The CVE-2015-0284 and CVE-2016-3079 issues were discovered by Jan Huta\u0159 (Red Hat).", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2016:0590", "url": "https://access.redhat.com/errata/RHSA-2016:0590" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#moderate", "url": "https://access.redhat.com/security/updates/classification/#moderate" }, { "category": "external", "summary": "1181152", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "category": "external", "summary": "1181472", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" }, { "category": "external", "summary": "1305677", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1305677" }, { "category": "external", "summary": "1305681", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1305681" }, { "category": "external", "summary": "1313515", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1313515" }, { "category": "external", "summary": "1313517", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1313517" }, { "category": "external", "summary": "1320444", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1320444" }, { "category": "external", "summary": "1320452", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1320452" }, { "category": "external", "summary": "1320940", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1320940" }, { "category": "self", "summary": "Canonical URL", "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_0590.json" } ], "title": "Red Hat Security Advisory: spacewalk-java security update", "tracking": { "current_release_date": "2024-11-22T09:57:18+00:00", "generator": { "date": "2024-11-22T09:57:18+00:00", "engine": { "name": "Red Hat SDEngine", "version": "4.2.1" } }, "id": "RHSA-2016:0590", "initial_release_date": "2016-04-04T15:35:36+00:00", "revision_history": [ { "date": "2016-04-04T15:35:36+00:00", "number": "1", "summary": "Initial version" }, { "date": "2016-04-04T15:35:36+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2024-11-22T09:57:18+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Satellite 5.7 (RHEL v.6)", "product": { "name": "Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57", "product_identification_helper": { "cpe": "cpe:/a:redhat:network_satellite:5.7::el6" } } } ], "category": "product_family", "name": "Red Hat Satellite" }, { "branches": [ { "category": "product_version", "name": "spacewalk-java-0:2.3.8-134.el6sat.src", "product": { "name": "spacewalk-java-0:2.3.8-134.el6sat.src", "product_id": "spacewalk-java-0:2.3.8-134.el6sat.src", "product_identification_helper": { "purl": "pkg:rpm/redhat/spacewalk-java@2.3.8-134.el6sat?arch=src" } } } ], "category": "architecture", "name": "src" }, { "branches": [ { "category": "product_version", "name": "spacewalk-java-0:2.3.8-134.el6sat.noarch", "product": { "name": "spacewalk-java-0:2.3.8-134.el6sat.noarch", "product_id": "spacewalk-java-0:2.3.8-134.el6sat.noarch", "product_identification_helper": { "purl": "pkg:rpm/redhat/spacewalk-java@2.3.8-134.el6sat?arch=noarch" } } }, { "category": "product_version", "name": "spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "product": { "name": "spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "product_id": "spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "product_identification_helper": { "purl": "pkg:rpm/redhat/spacewalk-java-oracle@2.3.8-134.el6sat?arch=noarch" } } }, { "category": "product_version", "name": "spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch", "product": { "name": "spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch", "product_id": "spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch", "product_identification_helper": { "purl": "pkg:rpm/redhat/spacewalk-taskomatic@2.3.8-134.el6sat?arch=noarch" } } }, { "category": "product_version", "name": "spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "product": { "name": "spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "product_id": "spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "product_identification_helper": { "purl": "pkg:rpm/redhat/spacewalk-java-postgresql@2.3.8-134.el6sat?arch=noarch" } } }, { "category": "product_version", "name": "spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "product": { "name": "spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "product_id": "spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "product_identification_helper": { "purl": "pkg:rpm/redhat/spacewalk-java-config@2.3.8-134.el6sat?arch=noarch" } } }, { "category": "product_version", "name": "spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "product": { "name": "spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "product_id": "spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "product_identification_helper": { "purl": "pkg:rpm/redhat/spacewalk-java-lib@2.3.8-134.el6sat?arch=noarch" } } } ], "category": "architecture", "name": "noarch" } ], "category": "vendor", "name": "Red Hat" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-0:2.3.8-134.el6sat.noarch as a component of Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch" }, "product_reference": "spacewalk-java-0:2.3.8-134.el6sat.noarch", "relates_to_product_reference": "6Server-Satellite57" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-0:2.3.8-134.el6sat.src as a component of Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src" }, "product_reference": "spacewalk-java-0:2.3.8-134.el6sat.src", "relates_to_product_reference": "6Server-Satellite57" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-config-0:2.3.8-134.el6sat.noarch as a component of Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch" }, "product_reference": "spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "relates_to_product_reference": "6Server-Satellite57" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-lib-0:2.3.8-134.el6sat.noarch as a component of Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch" }, "product_reference": "spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "relates_to_product_reference": "6Server-Satellite57" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch as a component of Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch" }, "product_reference": "spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "relates_to_product_reference": "6Server-Satellite57" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch as a component of Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch" }, "product_reference": "spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "relates_to_product_reference": "6Server-Satellite57" }, { "category": "default_component_of", "full_product_name": { "name": "spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch as a component of Red Hat Satellite 5.7 (RHEL v.6)", "product_id": "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" }, "product_reference": "spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch", "relates_to_product_reference": "6Server-Satellite57" } ] }, "vulnerabilities": [ { "acknowledgments": [ { "names": [ "Jan Huta\u0159" ], "organization": "Red Hat", "summary": "This issue was discovered by Red Hat." } ], "cve": "CVE-2015-0284", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)" }, "discovery_date": "2015-01-12T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1181472" } ], "notes": [ { "category": "description", "text": "A cross-site scripting (XSS) flaw was found in how XML data was handled in Red Hat Satellite. A user able to use the XMLRPC API could exploit this flaw to perform XSS attacks against other Satellite users.", "title": "Vulnerability description" }, { "category": "summary", "text": "Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2015-0284" }, { "category": "external", "summary": "RHBZ#1181472", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2015-0284", "url": "https://www.cve.org/CVERecord?id=CVE-2015-0284" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2015-0284", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-0284" } ], "release_date": "2015-03-03T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2016-04-04T15:35:36+00:00", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258", "product_ids": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2016:0590" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 3.5, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "version": "2.0" }, "products": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "Satellite: stored XSS in user details fields (incomplete fix for CVE-2014-7811)" }, { "cve": "CVE-2016-2103", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)" }, "discovery_date": "2016-01-21T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1305681" } ], "notes": [ { "category": "description", "text": "Multiple cross-site scripting (XSS) flaws were found in the way certain form data was handled in Red Hat Satellite. A user able to enter form data could use these flaws to perform XSS attacks against other Satellite users.", "title": "Vulnerability description" }, { "category": "summary", "text": "5: multiple stored XSS vulnerabilities", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2016-2103" }, { "category": "external", "summary": "RHBZ#1305681", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1305681" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2016-2103", "url": "https://www.cve.org/CVERecord?id=CVE-2016-2103" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2016-2103", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-2103" } ], "release_date": "2016-02-29T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2016-04-04T15:35:36+00:00", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258", "product_ids": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2016:0590" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "5: multiple stored XSS vulnerabilities" }, { "acknowledgments": [ { "names": [ "Adam Willard" ], "organization": "Raytheon Foreground Security" } ], "cve": "CVE-2016-2104", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)" }, "discovery_date": "2016-02-04T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1305677" } ], "notes": [ { "category": "description", "text": "Multiple cross-site scripting (XSS) flaws were found in the way HTTP GET parameter data was handled in Red Hat Satellite. A user able to provide malicious links to a Satellite user could use these flaws to perform XSS attacks against other Satellite users.", "title": "Vulnerability description" }, { "category": "summary", "text": "5: stored and reflected XSS vulnerabilities", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2016-2104" }, { "category": "external", "summary": "RHBZ#1305677", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1305677" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2016-2104", "url": "https://www.cve.org/CVERecord?id=CVE-2016-2104" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2016-2104", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-2104" } ], "release_date": "2016-02-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2016-04-04T15:35:36+00:00", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258", "product_ids": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2016:0590" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "5: stored and reflected XSS vulnerabilities" }, { "acknowledgments": [ { "names": [ "Jan Huta\u0159" ], "organization": "Red Hat", "summary": "This issue was discovered by Red Hat." } ], "cve": "CVE-2016-3079", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)" }, "discovery_date": "2016-03-23T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1320940" } ], "notes": [ { "category": "description", "text": "Multiple cross-site scripting (XSS) flaws were found in the way certain form data was handled in Red Hat Satellite. A user able to enter form data could use these flaws to perform XSS attacks against other Satellite users.", "title": "Vulnerability description" }, { "category": "summary", "text": "spacewalk-java: Multiple XSS issues in WebUI", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2016-3079" }, { "category": "external", "summary": "RHBZ#1320940", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1320940" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2016-3079", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3079" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2016-3079", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-3079" } ], "release_date": "2016-03-29T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "date": "2016-04-04T15:35:36+00:00", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258", "product_ids": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2016:0590" } ], "scores": [ { "cvss_v2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "version": "2.0" }, "products": [ "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-0:2.3.8-134.el6sat.src", "6Server-Satellite57:spacewalk-java-config-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-lib-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-oracle-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-java-postgresql-0:2.3.8-134.el6sat.noarch", "6Server-Satellite57:spacewalk-taskomatic-0:2.3.8-134.el6sat.noarch" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "spacewalk-java: Multiple XSS issues in WebUI" } ] }
ghsa-q4pf-r4w7-4wpv
Vulnerability from github
Published
2022-05-13 01:04
Modified
2022-05-13 01:04
Severity ?
VLAI Severity ?
Details
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
{ "affected": [], "aliases": [ "CVE-2015-0284" ], "database_specific": { "cwe_ids": [ "CWE-79" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2016-04-14T14:59:00Z", "severity": "MODERATE" }, "details": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.", "id": "GHSA-q4pf-r4w7-4wpv", "modified": "2022-05-13T01:04:03Z", "published": "2022-05-13T01:04:03Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-0284" }, { "type": "WEB", "url": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744" }, { "type": "WEB", "url": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794" }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2016:0590" }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2015-0284" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398" }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2016-0590.html" } ], "schema_version": "1.4.0", "severity": [ { "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "type": "CVSS_V3" } ] }
fkie_cve-2015-0284
Vulnerability from fkie_nvd
Published
2016-04-14 14:59
Modified
2025-04-12 10:46
Severity ?
Summary
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
References
▶ | URL | Tags | |
---|---|---|---|
secalert@redhat.com | http://rhn.redhat.com/errata/RHSA-2016-0590.html | Vendor Advisory | |
secalert@redhat.com | https://bugzilla.redhat.com/show_bug.cgi?id=1181152 | ||
secalert@redhat.com | https://bugzilla.redhat.com/show_bug.cgi?id=1181472 | ||
secalert@redhat.com | https://bugzilla.redhat.com/show_bug.cgi?id=1314906 | ||
secalert@redhat.com | https://bugzilla.redhat.com/show_bug.cgi?id=1315398 | ||
secalert@redhat.com | https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744 | ||
secalert@redhat.com | https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794 | ||
af854a3a-2127-422b-91ae-364da2661108 | http://rhn.redhat.com/errata/RHSA-2016-0590.html | Vendor Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://bugzilla.redhat.com/show_bug.cgi?id=1181152 | ||
af854a3a-2127-422b-91ae-364da2661108 | https://bugzilla.redhat.com/show_bug.cgi?id=1181472 | ||
af854a3a-2127-422b-91ae-364da2661108 | https://bugzilla.redhat.com/show_bug.cgi?id=1314906 | ||
af854a3a-2127-422b-91ae-364da2661108 | https://bugzilla.redhat.com/show_bug.cgi?id=1315398 | ||
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744 | ||
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794 |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
redhat | satellite | 5.7 | |
redhat | spacewalk-java | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*", "matchCriteriaId": "85EA16E0-9261-45C4-840F-5366E9EAC5E1", "vulnerable": true }, { "criteria": "cpe:2.3:a:redhat:spacewalk-java:-:*:*:*:*:*:*:*", "matchCriteriaId": "BB6F3D1C-DDF1-49B6-8E4D-38B037F33030", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811." }, { "lang": "es", "value": "Vulnerabilidad de XSS en spacewalk-java en Spacewalk y Red Hat Satellite 5.7 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s de datos XML manipulados en la API XMLRPC, involucrando detalles de usuario. NOTA: esta vulnerabilidad existe debido a una soluci\u00f3n incompleta para CVE-2014-7811." } ], "id": "CVE-2015-0284", "lastModified": "2025-04-12T10:46:40.837", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "LOW", "cvssData": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 3.5, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 6.8, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "version": "3.0" }, "exploitabilityScore": 2.3, "impactScore": 2.7, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2016-04-14T14:59:00.147", "references": [ { "source": "secalert@redhat.com", "tags": [ "Vendor Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-0590.html" }, { "source": "secalert@redhat.com", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "source": "secalert@redhat.com", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" }, { "source": "secalert@redhat.com", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906" }, { "source": "secalert@redhat.com", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398" }, { "source": "secalert@redhat.com", "url": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744" }, { "source": "secalert@redhat.com", "url": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ], "url": "http://rhn.redhat.com/errata/RHSA-2016-0590.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181152" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1181472" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1314906" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1315398" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://github.com/spacewalkproject/spacewalk/commit/dd418384171473c3e31386a1b4792f8c555dc744" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://github.com/spacewalkproject/spacewalk/commit/f3792c79c1c251a49cc4e382be8591636326a794" } ], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-79" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…