Skip to main content

Vendor/product archive

redhat / subscription_asset_manager CVEs

Beta · best-effort

11 CVEs tagged to redhat / subscription_asset_manager2 Critical, 2 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2014-0183

Published Jan 2, 2020

Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0029

Published Oct 16, 2017

Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6439

Published Dec 23, 2013

Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impa…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-1823

Published Apr 2, 2013

Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1