CVE-2015-0284
MEDIUMRedhat Satellite - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.
References (7)
Scores
CVSS v3
5.4
EPSS
0.0027
EPSS Percentile
50.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
redhat/satellite
redhat/spacewalk-java
Timeline
Published
Apr 14, 2016
Tracked Since
Feb 18, 2026