← Back

Subscription Asset Manager

subscription_asset_manager

Vendor: Redhat • 11 CVEs

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Nokogiri
Redhat
8Cloudforms Management Engine
Enterprise MrgNokogiri+5 more
Nov 21, 2024
Feb 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Nokogiri before 1.5.4 is vulnerable to XXE attacks
1Redhat
1Subscription Asset Manager
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
1Redhat
1Subscription Asset Manager
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
katello-headpin is vulnerable to CSRF in REST API
3Debian
NokogiriRedhat
7Cloudforms Management Engine
Debian LinuxEnterprise Mrg+4 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
3Debian
NokogiriRedhat
7Cloudforms Management Engine
Debian LinuxEnterprise Mrg+4 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
1Redhat
15Data Grid
Jboss A MqJboss Bpm Suite+12 more
May 13, 2026
Nov 9, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Ope...Show more
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.Show less
1Redhat
1Subscription Asset Manager
May 13, 2026
Oct 16, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
2Redhat
Rubyonrails
3Enterprise Linux Server
RailsSubscription Asset Manager
Apr 21, 2026
May 7, 2014
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbin...Show more
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.Show less
1Redhat
1Subscription Asset Manager
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.
1Redhat
1Subscription Asset Manager
Apr 29, 2026
Apr 2, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
2Candlepinproject
Redhat
2Candlepin
Subscription Asset Manager
Apr 29, 2026
Apr 2, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.