Vulnerabilities > CVE-2015-5164 - Deserialization of Untrusted Data vulnerability in Pulpproject Qpid

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
pulpproject
CWE-502

Summary

The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pickle processing problem in pulp.

Vulnerable Configurations

Part Description Count
Application
Pulpproject
1
OS
Redhat
1

Common Weakness Enumeration (CWE)