CVE-2010-2236
Summary
| CVE | CVE-2010-2236 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-15 23:55:00 UTC |
| Updated | 2022-02-03 16:26:00 UTC |
| Description | The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Network Proxy | 5.3 | All | All | All |
| Application | Redhat | Network Proxy | 5.3 | All | All | All |
| Application | Redhat | Network Satellite | 4.0 | All | All | All |
| Application | Redhat | Network Satellite | 4.1 | All | All | All |
| Application | Redhat | Network Satellite | 4.2 | All | All | All |
| Application | Redhat | Network Satellite | 5.1 | All | All | All |
| Application | Redhat | Network Satellite | 5.2 | All | All | All |
| Application | Redhat | Network Satellite | 5.3 | All | All | All |
| Application | Redhat | Network Satellite | 4.0 | All | All | All |
| Application | Redhat | Network Satellite | 4.1 | All | All | All |
| Application | Redhat | Network Satellite | 4.2 | All | All | All |
| Application | Redhat | Network Satellite | 5.1 | All | All | All |
| Application | Redhat | Network Satellite | 5.2 | All | All | All |
| Application | Redhat | Network Satellite | 5.3 | All | All | All |
| Application | Redhat | Satellite | 4.0 | All | All | All |
| Application | Redhat | Satellite | 4.1 | All | All | All |
| Application | Redhat | Satellite | 4.2 | All | All | All |
| Application | Redhat | Satellite | 5.1 | All | All | All |
| Application | Redhat | Satellite | 5.2 | All | All | All |
| Application | Redhat | Satellite | 5.3 | All | All | All |
| Application | Redhat | Spacewalk-java | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Attachment 819987 Details for Bug 607712 – Sanitize backticks in probes | MISC | bugzilla.redhat.com | |
| SUSE-SU-2014:0222-1 | SUSE | www.suse.com | |
| Security Advisory SA56952 - SUSE update for Multiple Spacewalk Packages - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| spacewalk.git - Spacewalk is an open source Linux and Solaris systems management solution. | CONFIRM | git.fedorahosted.org | Exploit, Patch |
| Infrastructure/Fedorahosted-retirement - Fedora Project Wiki | CONFIRM | git.fedorahosted.org | Exploit, Patch |
| 607712 – (CVE-2010-2236) CVE-2010-2236 RHN Satellite / Proxy: Improper monitoring probes input sanitization (ACE) | CONFIRM | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.