2024-12-08 03:06:42 +00:00

149 lines
4.4 KiB
JSON

{
"id": "CVE-2009-0788",
"sourceIdentifier": "secalert@redhat.com",
"published": "2011-04-18T17:55:00.843",
"lastModified": "2024-11-21T01:00:55.140",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors."
},
{
"lang": "es",
"value": "Red Hat Network (RHN) Satellite Server 5.3 y 5.4 no reescribe correctamente URLs no especificadas, lo que permite a atacantes remotos (1) obtener informaci\u00f3n sensible no especificado del anfitri\u00f3n o (2) utilizar el servidor como un proxy inadvertido para conectar con servicios y direcciones IP arbitrarios a trav\u00e9s de vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"baseScore": 6.4,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:network_satellite_server:5.3:*:*:*:*:*:*:*",
"matchCriteriaId": "1EC02C51-97F3-4014-B22D-0FC86F37E81B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:redhat:network_satellite_server:5.4:*:*:*:*:*:*:*",
"matchCriteriaId": "4C97A99B-1303-4B2B-8B06-799837D66A57"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/44150",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-0434.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/47316",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id?1025316",
"source": "secalert@redhat.com"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0967",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=491365",
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66691",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/44150",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2011-0434.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/47316",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1025316",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0967",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=491365",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66691",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}