CVE-2018-14666

MEDIUM

Red Hat Satellite 6.0-6.3 - Improper Authorization in Smart Class Feature

Title source: llm
STIX 2.1

Description

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106490
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666

Scores

CVSS v3 6.8
EPSS 0.0035
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-285 CWE-863
Status published
Products (1)
redhat/satellite 6.0 - 6.4
Published Jan 22, 2019
Tracked Since Feb 18, 2026