Show plain JSON{"affected_release": [{"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "foreman-0:1.11.0.51-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "foreman-installer-1:1.11.0.10-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "foreman-proxy-0:1.11.0.5-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "pulp-0:2.8.3.4-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "satellite-0:6.2.1-1.2.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "tfm-rubygem-foreman_discovery-0:5.0.0.9-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "tfm-rubygem-hammer_cli_foreman_admin-0:0.0.5-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "tfm-rubygem-hammer_cli_katello-0:0.0.22.25-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "tfm-rubygem-katello-0:3.0.0.70-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.1::el6", "package": "tfm-rubygem-ovirt_provision_plugin-0:1.0.2-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "foreman-0:1.11.0.51-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "foreman-installer-1:1.11.0.10-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "foreman-proxy-0:1.11.0.5-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "pulp-0:2.8.3.4-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "satellite-0:6.2.1-1.2.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "tfm-rubygem-foreman_discovery-0:5.0.0.9-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "tfm-rubygem-hammer_cli_foreman_admin-0:0.0.5-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "tfm-rubygem-hammer_cli_katello-0:0.0.22.25-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "tfm-rubygem-katello-0:3.0.0.70-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.1::el6", "package": "tfm-rubygem-ovirt_provision_plugin-0:1.0.2-1.el6sat", "product_name": "Red Hat Satellite 6.2 for RHEL 6", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "foreman-0:1.11.0.51-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "foreman-installer-1:1.11.0.10-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "foreman-proxy-0:1.11.0.5-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "pulp-0:2.8.3.4-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "satellite-0:6.2.1-1.2.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "tfm-rubygem-foreman_discovery-0:5.0.0.9-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "tfm-rubygem-hammer_cli_foreman_admin-0:0.0.5-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "tfm-rubygem-hammer_cli_katello-0:0.0.22.25-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "tfm-rubygem-katello-0:3.0.0.70-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite:6.2::el7", "package": "tfm-rubygem-ovirt_provision_plugin-0:1.0.2-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "foreman-0:1.11.0.51-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "foreman-installer-1:1.11.0.10-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "foreman-proxy-0:1.11.0.5-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "pulp-0:2.8.3.4-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "satellite-0:6.2.1-1.2.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "tfm-rubygem-foreman_discovery-0:5.0.0.9-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "tfm-rubygem-hammer_cli_foreman_admin-0:0.0.5-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "tfm-rubygem-hammer_cli_katello-0:0.0.22.25-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "tfm-rubygem-katello-0:3.0.0.70-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}, {"advisory": "RHBA-2016:1615", "cpe": "cpe:/a:redhat:satellite_capsule:6.2::el7", "package": "tfm-rubygem-ovirt_provision_plugin-0:1.0.2-1.el7sat", "product_name": "Red Hat Satellite 6.2 for RHEL 7", "release_date": "2016-08-16T00:00:00Z"}], "bugzilla": {"description": "foreman: API and UI actions/URLs not limited to the orgs/locations assigned", "id": "1342439", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1342439"}, "csaw": false, "cvss": {"cvss_base_score": "4.9", "cvss_scoring_vector": "AV:N/AC:M/Au:S/C:P/I:P/A:N", "status": "verified"}, "cwe": "CWE-284", "details": ["The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.", "It was found that the foreman API and UI actions and URLs are not properly limited to the organizations and locations they were assigned to. This could allow an attacker to view and update other organizations and locations in the system that they should not be allowed to."], "name": "CVE-2016-4475", "package_state": [{"cpe": "cpe:/a:redhat:openstack-installer:5", "fix_state": "Affected", "package_name": "foreman", "product_name": "OpenStack Foreman"}, {"cpe": "cpe:/a:redhat:ceph_storage:1.3", "fix_state": "Will not fix", "package_name": "foreman", "product_name": "Red Hat Ceph Storage 1.3"}, {"cpe": "cpe:/a:redhat:openstack-installer:6", "fix_state": "Affected", "package_name": "foreman", "product_name": "Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer"}], "public_date": "2016-06-02T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-4475\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-4475"], "threat_severity": "Moderate"}