MEDIUM · 6.0

CVE-2010-2236

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with...

Vulnerability Description

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
RedhatNetwork Proxy5.3
RedhatSatellite4.0
RedhatSpacewalk-Java<= 2.1.147-1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2236?

CVE-2010-2236 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with...

How severe is CVE-2010-2236?

CVE-2010-2236 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2236?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Network Proxy, Redhat Satellite, Redhat Spacewalk-Java.