Nils Juenemann reported that there is a cross-site scripting flaw in the filter for a result set in nearly every filter form provided by Red Hat Satellite (for example the "Filter by Synopsis" field). Acknowledgements: Red Hat would like to thank Nils Juenemann and The Bearded Warriors for independently reporting this issue.
This also affects upstream Spacewalk 1.4, as reported by The Bearded Warriors.
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.4 Via RHSA-2011:1299 https://rhn.redhat.com/errata/RHSA-2011-1299.html
Fixed in Spacewalk master, commit e91fab3da553f37d58aa43c067347010e8c95225, tagged as spacewalk-java-1.6.46-1.