Security Flaw in Satellite 5 Affects PostgreSQL Backend by Red Hat
CVE-2017-7513
5.4MEDIUM
Summary
A vulnerability exists in Red Hat's Satellite 5 when configured with SSL/TLS for the PostgreSQL backend. This flaw occurs due to improper validation of X.509 server certificate host name fields. As a result, a man-in-the-middle attacker could exploit this issue to impersonate a PostgreSQL server, leveraging a specially crafted X.509 certificate. Organizations utilizing Satellite 5 should take immediate measures to assess their configurations and implement necessary security updates to mitigate potential attacks.
Affected Version(s)
Red Hat Satellite 5
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved