CVE-2016-3080
Published on: 08/05/2016 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:03 PM UTC
Certain versions of Network Satellite from Redhat contain the following vulnerability:
Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters, related to display of monitoring probes.
- CVE-2016-3080 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
|
---|---|---|---|---|
NETWORK | LOW | NONE | REQUIRED | |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
|
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Bug 1320942 – CVE-2016-3080 spacewalk-monitoring: XSS issue in monitoring probe | Issue Tracking Vendor Advisory bugzilla.redhat.com text/html |
![]() |
Red Hat Customer Portal | Vendor Advisory web.archive.org text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Redhat | Network Satellite | 5.7 | All | All | All |
Application | Redhat | Network Satellite | 5.7 | All | All | All |
- cpe:2.3:a:redhat:network_satellite:5.7:*:*:*:*:*:*:*:
- cpe:2.3:a:redhat:network_satellite:5.7:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE