CVE-2016-3079: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATHINFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).
Other sources
Two XSS issues due to element creation in SSM (Perl stack) and displaying outside of it and two XSS issues on pages for entitlements management were reported.
Product bugs:
https://bugzilla.redhat.com/showbug.cgi?id=1320452 https://bugzilla.redhat.com/showbug.cgi?id=1320444
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3079?
CVE-2016-3079 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-3079?
To fix CVE-2016-3079, update Red Hat Satellite to version 5.7 or apply the necessary security patches as specified by Red Hat.
What types of attacks can CVE-2016-3079 enable?
CVE-2016-3079 can enable remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
Which versions of Red Hat Satellite are affected by CVE-2016-3079?
CVE-2016-3079 affects Red Hat Satellite version 5.7 and the Red Hat Spacewalk Java component.
What components are vulnerable in CVE-2016-3079?
The vulnerable components in CVE-2016-3079 include the Web UI, specifically systems/SystemEntitlements.do and admin/multiorg/EntitlementDetails.do.