Vulnerability CVE-2018-14666


Published: 2019-01-22

Description:
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.

Type:

CWE-863

(Incorrect Authorization)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Redhat -> Satellite 

 References:
http://www.securityfocus.com/bid/106490
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666

Copyright 2024, cxsecurity.com

 

Back to Top