First published: Mon Feb 08 2016(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Network Satellite Server | =5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2103 is classified as a moderate severity vulnerability due to its potential exploitation by attackers through cross-site scripting.
To fix CVE-2016-2103, update your Red Hat Satellite 5.7 installation to the latest patched version provided by Red Hat.
The potential impacts of CVE-2016-2103 include unauthorized access to sensitive information and the ability to execute arbitrary scripts in the context of the user’s session.
CVE-2016-2103 affects Red Hat Satellite version 5.7.
Yes, CVE-2016-2103 can be exploited remotely by attackers via crafted parameters in HTTP requests.