CVE-2015-5164 Information
Feb 14, 2021
cve
Description
The Qpid server on Red Hat Satellite 6 does not properly restrict message types which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message related to a pickle processing problem in pulp.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=1247732 https://pulp.plan.io/issues/23
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: