Bug 1126961

Summary: Satellite 6 does not provide a way to search content based on CVE/MITRE/OVAL data
Product: Red Hat Satellite Reporter: Rich Jerrido <rjerrido>
Component: Content ManagementAssignee: Justin Sherrill <jsherril>
Status: CLOSED ERRATA QA Contact: jcallaha
Severity: medium Docs Contact:
Priority: unspecified    
Version: UnspecifiedCC: bbuckingham, ejacobs, jcallaha, jfenal, kybaker, riehecky, stbenjam, tomckay
Target Milestone: UnspecifiedKeywords: Reopened, Triaged
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-08-12 05:13:32 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1124992    
Bug Blocks:    

Description Rich Jerrido 2014-08-05 18:24:39 UTC
Description of problem:

Satellite 6 doesn't provide a means to search for a erratum based upon a CVE identifier, such as CVE-2014-3145. 

Searching by this very easily gave the ability to determine:
* What Red Hat Security Advisory (RHSA) does this map back to 
* and (most importantly) What systems are affected by the vulnerability

This capability is used very heavily by existing Satellite 5 customers & not having this capability will be seen as a fairly large regression.

Comment 1 RHEL Program Management 2014-08-05 18:34:01 UTC
Since this issue was entered in Red Hat Bugzilla, the release flag has been
set to ? to ensure that it is properly evaluated for this release.

Comment 3 Tom McKay 2014-08-05 18:45:29 UTC

*** This bug has been marked as a duplicate of bug 1124992 ***

Comment 4 Tom McKay 2014-08-05 20:01:47 UTC
Adding 1124992 as a "depends on" but it's really just related.

Comment 5 Stephen Benjamin 2014-12-02 14:01:54 UTC
Errata can now be searched by CVE, e.g. "cve = CVE-2014-1111"

Fixed upstream in katello|2ef156aad07963f3f19553010d40b67cde7e1866

Comment 8 jcallaha 2015-04-02 17:44:44 UTC
Verified by QE on version Satellite-6.1.0-RHEL-7-20150331.1

Comment 9 Bryan Kearney 2015-08-11 13:32:02 UTC
This bug is slated to be released with Satellite 6.1.

Comment 10 errata-xmlrpc 2015-08-12 05:13:32 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2015:1592