Security Flaw in Satellite 5 Affects PostgreSQL Backend by Red Hat
CVE-2017-7513

5.4MEDIUM

Key Information:

Vendor
Red Hat
Vendor
CVE Published:
22 August 2018

Summary

A vulnerability exists in Red Hat's Satellite 5 when configured with SSL/TLS for the PostgreSQL backend. This flaw occurs due to improper validation of X.509 server certificate host name fields. As a result, a man-in-the-middle attacker could exploit this issue to impersonate a PostgreSQL server, leveraging a specially crafted X.509 certificate. Organizations utilizing Satellite 5 should take immediate measures to assess their configurations and implement necessary security updates to mitigate potential attacks.

Affected Version(s)

Red Hat Satellite 5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.