VulnerabilityModified
CVE-2016-3080
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters, related to display of monitoring probes.
MEDIUM 6.1EPSS 1.07%
Does this matter?
Lower severity and a low EPSS score (1.07%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters, related to display of monitoring probes.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- redhat/satellite
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-1484.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1320942Issue Tracking, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1484.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1320942Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.