Vulnerabilities > Redhat > Spacewalk > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-02-17 CVE-2020-1693 XXE vulnerability in Redhat Spacewalk 1.6/2.6
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint.
network
low complexity
redhat CWE-611
critical
9.8
2019-07-02 CVE-2019-10137 Unspecified vulnerability in Redhat Satellite and Spacewalk
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens.
network
low complexity
redhat
critical
9.8
2018-07-27 CVE-2017-7470 Unspecified vulnerability in Redhat Satellite and Spacewalk
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
network
low complexity
redhat
critical
9.8