CVE-2009-4139
Summary
| CVE | CVE-2009-4139 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-07-27 02:55:00 UTC |
| Updated | 2017-08-17 01:31:00 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in the Spacewalk Java site packages (aka spacewalk-java) 1.2.39 in Spacewalk, as used in the server in Red Hat Network Satellite 5.3.0 through 5.4.1 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that (1) disable the current user account, (2) add user accounts, or (3) modify user accounts to have administrator privileges. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Network Satellite Server | 5.3.0 | All | All | All |
| Application | Redhat | Network Satellite Server | 5.4.0 | All | All | All |
| Application | Redhat | Network Satellite Server | 5.4.1 | All | All | All |
| Application | Redhat | Network Satellite Server | 5.3.0 | All | All | All |
| Application | Redhat | Network Satellite Server | 5.4.0 | All | All | All |
| Application | Redhat | Network Satellite Server | 5.4.1 | All | All | All |
| Application | Redhat | Spacewalk-java | 1.2.39 | All | All | All |
| Application | Redhat | Spacewalk-java | 1.2.39 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Network Satellite Server Request Validation Flaw Permits Cross-Site Request Forgery Attacks - SecurityTracker | SECTRACK | securitytracker.com | |
| Support | REDHAT | www.redhat.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Bug 529483 – CVE-2009-4139 RHN Satellite / Spacewalk: CSRF in all web portal forms | CONFIRM | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.