Mickaël Gallier reports: There are several stored XSS vulnerabilities in various fields in Satellite server, they can be exploited by using the REST API to send XML data containing malformed data.
Created attachment 951111 [details] SW-master/Sat5-latest patch This patch applies to the latest Spacewalk and Satellite5 codebase. Sat5.6 patch is still in progress.
Created attachment 951859 [details] Sat5.6 patch This patch applies to the 5.6 branch of the Satellite codebase
Acknowledgement: Red Hat would like to thank Mickaël Gallier for reporting this issue.
This issue has been addressed in the following products: Red Hat Satellite Server v 5.7 Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html