<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2009-0788</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2009-0788</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>4</Number>
        <Date>2024-07-26T02:26:36Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T12:46:09Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-07-26T02:26:36Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2009-0788</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Manager Proxy Module 4.3">
      <Branch Type="Product Name" Name="SUSE Manager Proxy Module 4.3">
        <FullProductName ProductID="SUSE Manager Proxy Module 4.3" CPE="cpe:/o:suse:sle-module-suse-manager-proxy:4.3">SUSE Manager Proxy Module 4.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server Module 4.3">
      <Branch Type="Product Name" Name="SUSE Manager Server Module 4.3">
        <FullProductName ProductID="SUSE Manager Server Module 4.3" CPE="cpe:/o:suse:sle-module-suse-manager-server:4.3">SUSE Manager Server Module 4.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend">
      <FullProductName ProductID="spacewalk-backend">spacewalk-backend</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-app">
      <FullProductName ProductID="spacewalk-backend-app">spacewalk-backend-app</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-applet">
      <FullProductName ProductID="spacewalk-backend-applet">spacewalk-backend-applet</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files">
      <FullProductName ProductID="spacewalk-backend-config-files">spacewalk-backend-config-files</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-common">
      <FullProductName ProductID="spacewalk-backend-config-files-common">spacewalk-backend-config-files-common</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-config-files-tool">
      <FullProductName ProductID="spacewalk-backend-config-files-tool">spacewalk-backend-config-files-tool</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-iss">
      <FullProductName ProductID="spacewalk-backend-iss">spacewalk-backend-iss</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-iss-export">
      <FullProductName ProductID="spacewalk-backend-iss-export">spacewalk-backend-iss-export</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-package-push-server">
      <FullProductName ProductID="spacewalk-backend-package-push-server">spacewalk-backend-package-push-server</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-server">
      <FullProductName ProductID="spacewalk-backend-server">spacewalk-backend-server</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql">
      <FullProductName ProductID="spacewalk-backend-sql">spacewalk-backend-sql</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-sql-postgresql">
      <FullProductName ProductID="spacewalk-backend-sql-postgresql">spacewalk-backend-sql-postgresql</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-tools">
      <FullProductName ProductID="spacewalk-backend-tools">spacewalk-backend-tools</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-xml-export-libs">
      <FullProductName ProductID="spacewalk-backend-xml-export-libs">spacewalk-backend-xml-export-libs</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="spacewalk-backend-xmlrpc">
      <FullProductName ProductID="spacewalk-backend-xmlrpc">spacewalk-backend-xmlrpc</FullProductName>
    </Branch>
    <Relationship ProductReference="spacewalk-backend" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy Module 4.3">
      <FullProductName ProductID="SUSE Manager Proxy Module 4.3:spacewalk-backend">spacewalk-backend as a component of SUSE Manager Proxy Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend">spacewalk-backend as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-app" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-app">spacewalk-backend-app as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-applet" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-applet">spacewalk-backend-applet as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-config-files">spacewalk-backend-config-files as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-common" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-config-files-common">spacewalk-backend-config-files-common as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-config-files-tool" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-config-files-tool">spacewalk-backend-config-files-tool as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-iss" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-iss">spacewalk-backend-iss as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-iss-export" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-iss-export">spacewalk-backend-iss-export as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-package-push-server" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-package-push-server">spacewalk-backend-package-push-server as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-server" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-server">spacewalk-backend-server as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-sql">spacewalk-backend-sql as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-sql-postgresql" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-sql-postgresql">spacewalk-backend-sql-postgresql as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-tools" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-tools">spacewalk-backend-tools as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-xml-export-libs" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-xml-export-libs">spacewalk-backend-xml-export-libs as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="spacewalk-backend-xmlrpc" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server Module 4.3">
      <FullProductName ProductID="SUSE Manager Server Module 4.3:spacewalk-backend-xmlrpc">spacewalk-backend-xmlrpc as a component of SUSE Manager Server Module 4.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.</Note>
    </Notes>
    <CVE>CVE-2009-0788</CVE>
    <ProductStatuses>
      <Status Type="Known Not Affected">
        <ProductID>SUSE Manager Proxy Module 4.3:spacewalk-backend</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-app</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-applet</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-config-files</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-config-files-common</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-config-files-tool</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-iss</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-iss-export</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-package-push-server</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-server</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-sql</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-sql-postgresql</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-tools</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-xml-export-libs</ProductID>
        <ProductID>SUSE Manager Server Module 4.3:spacewalk-backend-xmlrpc</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:P/A:N</VectorV2>
      </ScoreSetV2>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
