CVE-2009-4139

A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or escalating privileges by modifying existing user accounts to have administrator access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:network_satellite_server:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite_server:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:network_satellite_server:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:spacewalk-java:1.2.39:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-07-27 02:55

Updated : 2026-06-16 23:13


NVD link : CVE-2009-4139

Mitre link : CVE-2009-4139

CVE.ORG link : CVE-2009-4139


JSON object : View

Products Affected

redhat

  • network_satellite_server
  • spacewalk-java
CWE
CWE-346

Origin Validation Error

CWE-352

Cross-Site Request Forgery (CSRF)