REDHAT-BUG-1192249: Medium severity red hat satellite with embedded oracle vulnerability
In Red Hat Satellite, the MongoDB database can be accessed by any malicious local user of the Satellite server and pulpdatabase content can be modified or deleted. Embedded MongoDB was introduced in Satellite 6.0 onward therefore, all the current Satellite active versions are affected by the flaw.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1192249?
The severity of REDHAT-BUG-1192249 is considered critical due to unauthorized access to the MongoDB database.
How do I fix REDHAT-BUG-1192249?
To fix REDHAT-BUG-1192249, apply the latest security patches provided by Red Hat for Satellite.
Which versions of Red Hat Satellite are affected by REDHAT-BUG-1192249?
All active versions of Red Hat Satellite starting from version 6.0 are affected by REDHAT-BUG-1192249.
What type of database is involved in REDHAT-BUG-1192249?
REDHAT-BUG-1192249 involves an embedded MongoDB database used by Red Hat Satellite.
Can a remote attacker exploit REDHAT-BUG-1192249?
No, REDHAT-BUG-1192249 can only be exploited by malicious local users with access to the Satellite server.