QID 238192

Date Published: 2021-06-16

QID 238192: Red Hat Update for Satellite 6.7 release.(RHSA-2020:1454)

Red Hat Satellite is a systems management tool for Linux-based infrastructure. It allows for provisioning, remote management, and monitoring of multiple Linux deployments with a single centralized tool.

Security Fix(es): apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)
jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server (CVE-2019-12086)
mina-core: Retaining an open socket in close_notify SSL-TLS leading to Information disclosure (CVE-2019-0231)

Affected Products:

Red Hat Satellite 6.7 x86_64
Red Hat Satellite Capsule 6.7 x86_64

On successful exploitation it could allow an attacker to execute code.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to Applying Package Updates to RHEL system for details.

    Refer to Red Hat security advisory RHSA-2020:1454 to address this issue and obtain more information.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    RHSA-2020:1454 Red Hat Enterprise Linux URL Logo access.redhat.com/errata/RHSA-2020:1454