Vulnerabilities > Redhat > Subscription Asset Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-02 CVE-2014-0183 Cross-site Scripting vulnerability in Redhat Subscription Asset Manager 1.4.0
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
network
low complexity
redhat CWE-79
6.1
2019-12-11 CVE-2014-0026 Cross-Site Request Forgery (CSRF) vulnerability in Redhat Subscription Asset Manager 1.0.0
katello-headpin is vulnerable to CSRF in REST API
network
low complexity
redhat CWE-352
6.5
2019-11-05 CVE-2013-6461 XML Entity Expansion vulnerability in multiple products
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
network
low complexity
nokogiri debian redhat CWE-776
6.5
2019-11-05 CVE-2013-6460 XML Entity Expansion vulnerability in multiple products
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
network
low complexity
nokogiri debian redhat CWE-776
6.5
2017-10-16 CVE-2014-0029 Cross-site Scripting vulnerability in Redhat Subscription Asset Manager 1.0.0
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
low complexity
redhat CWE-79
6.1