Subscription Asset Manager
Vendor:
First CVE: Apr 2, 2013 · Active for 13 years
11
Total CVEs
More Total CVEs than 90% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
9.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Subscription Asset Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 2, 2013
13 years ago
Most Recent CVE
Feb 19, 2020
2,351 days ago
CVE Severity & Scoring
Subscription Asset Manager11 CVEs
9%
55%
27%
9%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (72.7%)
Unknown3 (27.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (72.7%)
High0 (0.0%)
Unknown3 (27.3%)
User Interaction
None3 (27.3%)
Unknown3 (27.3%)
Required5 (45.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (72.7%)
Unknown3 (27.3%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0130HIGH Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x | May 7, 2014 | 7.5 | 83 | YES | NO |
CVE-2015-7501CRITICAL Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fus | Nov 9, 2017 | 9.8 | 74 | NO | NO |
CVE-2012-6685HIGH Nokogiri before 1.5.4 is vulnerable to XXE attacks | Feb 19, 2020 | 7.5 | 24 | NO | NO |
CVE-2013-6439HIGH Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impac | Dec 23, 2013 | 9.3 | 23 | NO | NO |
CVE-2013-6460MEDIUM Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents | Nov 5, 2019 | 6.5 | 21 | NO | NO |
CVE-2014-0029MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecif | Oct 16, 2017 | 6.1 | 21 | NO | NO |
CVE-2014-0183MEDIUM Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. | Jan 2, 2020 | 6.1 | 20 | NO | NO |
CVE-2014-0026MEDIUM katello-headpin is vulnerable to CSRF in REST API | Dec 11, 2019 | 6.5 | 20 | NO | NO |
CVE-2013-6461MEDIUM Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits | Nov 5, 2019 | 6.5 | 18 | NO | NO |
CVE-2013-1823MEDIUM Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML | Apr 2, 2013 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
1 CVE
9.1% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Subscription Asset Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.4.0 | 1 | 6.1 | 0.7% | 0 | 0 |
| 1.3.0 | 2 | 9.6 | 42.4% | 0 | 0 |
| 1.2.1 | 1 | 9.3 | 1.6% | 0 | 0 |
| 1.2.0 | 1 | 9.3 | 1.6% | 0 | 0 |
| 1.1.0 | 3 | 5.2 | 1.3% | 0 | 0 |
| 1.0.0 | 5 | 5.7 | 1.0% | 0 | 0 |