First published: Mon May 12 2008(Updated: )
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
rPath Appliance Platform Agent | =3 | |
rPath Appliance Platform Agent | =2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2140 is considered a high-severity vulnerability due to its potential to allow attackers to reset the root password.
To fix CVE-2008-2140, update the rPath Appliance Platform Agent to the latest version that has patched this vulnerability.
CVE-2008-2140 affects rPath Appliance Platform Agent versions 2 and 3.
CVE-2008-2140 is a Cross-site request forgery (CSRF) vulnerability.
Attackers can exploit CVE-2008-2140 to reset the root password on the affected systems.