CVE-2010-2236: Input Validation
An improper input sanitization flaw was found in the way Red Hat Network Satellite performed management of monitoring probes. A remote, authenticated attacker, with the privilege to administer monitoring probes, could execute arbitrary code with the privileges of the user, the Red Hat Network Satellite monitoring service is running under, by providing a specially-crafted values for certain options of the monitoring probe display.
References: For further information about Red Hat Network Satellite monitoring entitlements and management of monitoring probes, please refer to the reference guide of your Red Hat Network Satellite installation.
Other sources
The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2236?
CVE-2010-2236 has been classified as having a moderate severity due to the potential for remote code execution by authenticated attackers.
How do I fix CVE-2010-2236?
To remediate CVE-2010-2236, upgrade to the latest patched version of Red Hat Satellite or associated products that address this vulnerability.
Who is affected by CVE-2010-2236?
CVE-2010-2236 affects users of Red Hat Satellite, Network Proxy, and Spacewalk Java, specifically in the specified vulnerable versions.
What action can an attacker perform due to CVE-2010-2236?
An attacker exploiting CVE-2010-2236 can execute arbitrary code with the privileges of the Red Hat Network Satellite user.
What type of vulnerability is CVE-2010-2236?
CVE-2010-2236 represents an improper input sanitization vulnerability that allows for arbitrary code execution.