REDHAT-BUG-1873926: High severity red hat satellite with embedded oracle vulnerability
Published Aug 31, 2020
·Updated
A account takeover flaw was found in Red Hat Satellite 6.7.2 onward, a potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.
Affected Software
1 affected component
Red Hat Satellite>=6.7.2
Event History
Aug 31, 2020
Data Sourced
via Red Hat·03:57 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1873926?
The severity of REDHAT-BUG-1873926 is considered high due to the potential for account takeover.
2
How do I fix REDHAT-BUG-1873926?
To fix REDHAT-BUG-1873926, update your Red Hat Satellite software to the latest patched version.
3
Who is affected by REDHAT-BUG-1873926?
REDHAT-BUG-1873926 affects users of Red Hat Satellite 6.7.2 and later who utilize external authentication sources.
4
What type of vulnerability is REDHAT-BUG-1873926?
REDHAT-BUG-1873926 is classified as an account takeover vulnerability.
5
Can an external attacker exploit REDHAT-BUG-1873926?
Yes, an external attacker with proper authentication can exploit REDHAT-BUG-1873926 to take over existing user accounts.