Spacewalk Java
Vendor:
First CVE: Jul 27, 2011 · Active for 14 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spacewalk Java over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2011
14 years ago
Most Recent CVE
Apr 14, 2016
3,753 days ago
CVE Severity & Scoring
Spacewalk Java9 CVEs
11%
89%
All CVEs352,231 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local0 (0.0%)
Network3 (33.3%)
Unknown6 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (22.2%)
High1 (11.1%)
Unknown6 (66.7%)
User Interaction
None0 (0.0%)
Unknown6 (66.7%)
Required3 (33.3%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None2 (22.2%)
Unknown6 (66.7%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3079MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the P | Apr 14, 2016 | 6.1 | 21 | NO | NO |
CVE-2010-2236MEDIUM The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote auth | Apr 15, 2014 | 6.0 | 20 | NO | NO |
CVE-2009-4139MEDIUM A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. Thi | Jul 27, 2011 | 6.8 | 20 | NO | NO |
CVE-2014-3654MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary | Nov 3, 2014 | 4.3 | 18 | NO | NO |
CVE-2014-3595MEDIUM Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inj | Sep 22, 2014 | 4.3 | 18 | NO | NO |
CVE-2013-1869MEDIUM CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP r | Apr 1, 2014 | 4.3 | 17 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web scr | Feb 14, 2014 | 3.5 | 17 | NO | NO |
CVE-2015-0284MEDIUM Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via craft | Apr 14, 2016 | 5.4 | 16 | NO | NO |
CVE-2013-4415MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) w | Feb 14, 2014 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Spacewalk Java
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.2-57 | 1 | 3.5 | 1.6% | 0 | 0 |
| 2.0.2 | 2 | 4.3 | 1.8% | 0 | 0 |
| 1.7.54 | 1 | 4.3 | 1.8% | 0 | 0 |
| 1.2.39 | 2 | 5.5 | 1.3% | 0 | 0 |