VulnerabilityModified
CVE-2011-4346
Cross-site scripting (XSS) vulnerability in the web interface in Red Hat Network (RHN) Satellite 5.4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field of the asset tag in a Custom Info page.
LOW 3.5EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the web interface in Red Hat Network (RHN) Satellite 5.4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field of the asset tag in a Custom Info page.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- redhat/satellite
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/47162Broken Link
- http://www.redhat.com/support/errata/RHSA-2011-1794.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/50963Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026391Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=742050Issue Tracking
- http://secunia.com/advisories/47162Broken Link
- http://www.redhat.com/support/errata/RHSA-2011-1794.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/50963Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026391Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=742050Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.