MEDIUM
rhpki-ra: improper authorization checks in Cerificate System's Registration Authority
Published May 27, 2009
6.5
MEDIUMCVSS 2.0
EPSS 1.31%
Description
agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.
Affected products
No data.
OR
- 7.3
- n/a
No data.
Red Hat Certificate System 7.3
rhpki-ra-0:7.3.0-69.el4
Fixed · RHSA-2009:1065
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Certificate System 7.3 | rhpki-ra-0:7.3.0-69.el4 | Fixed | RHSA-2009:1065 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (10)
- http://secunia.com/advisories/35242 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35263 third-party-advisoryx_refsource_SECUNIA
- http://www.redhat.com/support/errata/RHSA-2009-1065.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://www.securityfocus.com/bid/35104 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022278 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2009-0588 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=484828 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=488706 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-0588
- https://www.cve.org/CVERecord?id=CVE-2009-0588
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/35242 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/advisories/35263 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.redhat.com/support/errata/RHSA-2009-1065.html | vendor-advisoryx_refsource_REDHATPatchVendor Advisory | |
| http://www.securityfocus.com/bid/35104 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id?1022278 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2009-0588 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=484828 | x_refsource_CONFIRMPatch | |
| https://bugzilla.redhat.com/show_bug.cgi?id=488706 | x_refsource_CONFIRMIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-0588 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-0588 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 27, 2009
Updated Aug 7, 2024
Reserved Feb 13, 2009
Link CVE-2009-0588
CISA Vulnrichment
Updated n/a