VulnerabilityModified
CVE-2009-0588
agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified…
MEDIUM 6.5EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- redhat/certificate system · redhat/dogtag certificate system
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/35242
- http://secunia.com/advisories/35263
- http://www.redhat.com/support/errata/RHSA-2009-1065.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35104
- http://www.securitytracker.com/id?1022278
- https://bugzilla.redhat.com/show_bug.cgi?id=484828Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=488706
- http://secunia.com/advisories/35242
- http://secunia.com/advisories/35263
- http://www.redhat.com/support/errata/RHSA-2009-1065.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35104
- http://www.securitytracker.com/id?1022278
- https://bugzilla.redhat.com/show_bug.cgi?id=484828Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=488706
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.