The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.
References
Link | Resource |
---|---|
http://www.osvdb.org/93566 | |
http://rhn.redhat.com/errata/RHSA-2013-0848.html | Vendor Advisory |
http://secunia.com/advisories/53487 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-07-31 06:20
Updated : 2022-02-03 08:26
NVD link : CVE-2013-2056
Mitre link : CVE-2013-2056
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
redhat
- satellite