PT-2011-1364 · Red Hat · Red Hat Network Satellite
Vincent Danen
·
Published
2011-04-18
·
Updated
2022-02-19
·
CVE-2010-1171
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Network (RHN) Satellite versions 5.3 through 5.4
Description
The issue allows remote authenticated users to access arbitrary files and cause a denial of service, specifically failed yum operations, via vectors related to configuration and package group (comps.xml) files for channels. This is due to the exposure of a dangerous, obsolete XML-RPC API.
Recommendations
For versions 5.3 and 5.4, consider disabling the obsolete XML-RPC API as a temporary workaround until a patch is available. Restrict access to configuration and package group files, such as comps.xml, to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Network Satellite