Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/46528 | vdb entry |
http://www.vupen.com/english/advisories/2011/0491 | vdb entry vendor advisory |
http://www.redhat.com/support/errata/RHSA-2011-0300.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=672159 | |
http://www.securitytracker.com/id?1025116 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65657 | vdb entry |
http://secunia.com/advisories/43487 | third party advisory vendor advisory |