First published: Thu Jan 15 2015(Updated: )
Cross-site scripting (XSS) vulnerability in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allows remote authenticated users to inject arbitrary web script or HTML via the System Groups field.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Satellite | =5.6 | |
Red Hat Spacewalk | ||
SUSE Manager Server | =1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7812 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-7812, upgrade to Spacewalk or Red Hat Satellite version 5.7.0 or later where the vulnerability has been addressed.
CVE-2014-7812 affects users of Spacewalk and Red Hat Network Satellite versions prior to 5.7.0.
CVE-2014-7812 enables remote authenticated users to perform cross-site scripting (XSS) attacks.
No, CVE-2014-7812 requires remote authentication to exploit the XSS vulnerability.