CVE-2012-6149: Red Hat Satellite

Low severity, CVSS 3.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.

Affected products

  • Red Hat Satellite: version 5.6 only
  • Red Hat Satellite 5 Managed DB: version 5.6 only
  • Red Hat Spacewalk-Java: version 2.0.2-57 only

Published 2014-02-14. Last modified 2026-06-16.