Vulnerability Description
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Network Proxy | 5.3 |
| Redhat | Satellite | 4.0 |
| Redhat | Spacewalk-Java | <= 2.1.147-1 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/56952Vendor Advisory
- https://bugzilla.redhat.com/attachment.cgi?id=819987&action=diff
- https://bugzilla.redhat.com/show_bug.cgi?id=607712
- https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ExploitPatch
- https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=c41c87a9dc9dac771eb76ExploitPatch
- https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html
- http://secunia.com/advisories/56952Vendor Advisory
- https://bugzilla.redhat.com/attachment.cgi?id=819987&action=diff
- https://bugzilla.redhat.com/show_bug.cgi?id=607712
- https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=18c70164285cae0660fa3ExploitPatch
- https://git.fedorahosted.org/cgit/spacewalk.git/commit/?id=c41c87a9dc9dac771eb76ExploitPatch
- https://www.suse.com/support/update/announcement/2014/suse-su-20140222-1.html
FAQ
What is CVE-2010-2236?
CVE-2010-2236 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with...
How severe is CVE-2010-2236?
CVE-2010-2236 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2236?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Network Proxy, Redhat Satellite, Redhat Spacewalk-Java.