CVE-2009-4139 Information
Feb 14, 2021
cve
Description
Cross-site request forgery (CSRF) vulnerability in the Spacewalk Java site packages (aka spacewalk-java) 1.2.39 in Spacewalk as used in the server in Red Hat Network Satellite 5.3.0 through 5.4.1 and other products allows remote attackers to hijack the authentication of arbitrary users for requests that (1) disable the current user account (2) add user accounts or (3) modify user accounts to have administrator privileges.
Reference
http://securitytracker.com/id?1025674 http://www.redhat.com/support/errata/RHSA-2011-0879.html https://bugzilla.redhat.com/show_bug.cgi?id=529483 https://exchange.xforce.ibmcloud.com/vulnerabilities/68074
Share on: