CVE-2016-3097: XSS
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.
Other sources
Group name is not properly escaped allowing XSS
An XSS vulnerability was found in WebUI when creating group with HTML via SSM or API and checking snapshot with this group join/leave.
Product bug:
https://bugzilla.redhat.com/showbug.cgi?id=1322710
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3097?
CVE-2016-3097 is categorized as a medium severity vulnerability due to its ability to facilitate cross-site scripting attacks.
How do I fix CVE-2016-3097?
To address CVE-2016-3097, it is recommended to upgrade to the latest version of Red Hat Satellite that addresses this XSS vulnerability.
What version of Red Hat Satellite is affected by CVE-2016-3097?
CVE-2016-3097 specifically affects Red Hat Satellite version 5.7.
Can CVE-2016-3097 be exploited remotely?
Yes, CVE-2016-3097 can be exploited remotely by attackers through crafted group names that inject malicious scripts.
What type of vulnerability is CVE-2016-3097?
CVE-2016-3097 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.