CVE-2013-4480

Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:network_satellite:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.5:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:suse:manager:1.7:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:11.0:sp2:*:*:*:*:*:*

History

13 Feb 2023, 04:47

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2013-4480', 'name': 'https://access.redhat.com/security/cve/CVE-2013-4480', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2013:1513', 'name': 'https://access.redhat.com/errata/RHSA-2013:1513', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2013:1514', 'name': 'https://access.redhat.com/errata/RHSA-2013:1514', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2013-4480 Satellite: Interface to create the initial administrator user remains open after installation Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.

02 Feb 2023, 20:15

Type Values Removed Values Added
Summary Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts. CVE-2013-4480 Satellite: Interface to create the initial administrator user remains open after installation
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2013-4480 -
  • (MISC) https://access.redhat.com/errata/RHSA-2013:1513 -
  • (MISC) https://access.redhat.com/errata/RHSA-2013:1514 -

25 Feb 2022, 19:17

Type Values Removed Values Added
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00009.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00009.html - Mailing List, Patch, Vendor Advisory
References (CONFIRM) https://bugzilla.redhat.com/show_bug.cgi?id=1024614 - (CONFIRM) https://bugzilla.redhat.com/show_bug.cgi?id=1024614 - Issue Tracking, Vendor Advisory
First Time Suse manager
Redhat satellite With Embedded Oracle
Suse linux Enterprise
Suse
CWE CWE-264 CWE-668
CPE cpe:2.3:a:redhat:satellite:5.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:3.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:4.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:4.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.2:*:*:*:*:*:*:*
cpe:2.3:a:suse:manager:1.7:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:11.0:sp2:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite_with_embedded_oracle:5.4:*:*:*:*:*:*:*

03 Feb 2022, 16:26

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:network_satellite:3.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite:4.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite:5.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite:5.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite:5.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite:5.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite:4.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:3.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:4.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:4.2:*:*:*:*:*:*:*
First Time Redhat satellite

Information

Published : 2013-11-18 02:55

Updated : 2023-12-10 11:16


NVD link : CVE-2013-4480

Mitre link : CVE-2013-4480

CVE.ORG link : CVE-2013-4480


JSON object : View

Products Affected

suse

  • linux_enterprise
  • manager

redhat

  • network_satellite
  • satellite
  • satellite_with_embedded_oracle
CWE
CWE-668

Exposure of Resource to Wrong Sphere