CVE-2009-0788

high

Description

Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/66691

https://bugzilla.redhat.com/show_bug.cgi?id=491365

http://www.vupen.com/english/advisories/2011/0967

http://www.securitytracker.com/id?1025316

http://www.securityfocus.com/bid/47316

http://www.redhat.com/support/errata/RHSA-2011-0434.html

http://secunia.com/advisories/44150

Details

Source: Mitre, NVD

Published: 2011-04-18

Updated: 2017-08-17

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High