Vulnerabilities > Redhat > Spacewalk > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-02-17 CVE-2020-1693 XXE vulnerability in Redhat Spacewalk 1.6/2.6/2.9
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint.
network
low complexity
redhat CWE-611
critical
9.8
2019-07-02 CVE-2019-10137 Path Traversal vulnerability in Redhat Satellite and Spacewalk
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens.
network
low complexity
redhat CWE-22
critical
9.8
2018-07-27 CVE-2017-7470 Incorrect Authorization vulnerability in Redhat Satellite and Spacewalk
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
network
low complexity
redhat CWE-863
critical
9.8