First published: Thu Mar 05 2009(Updated: )
agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Certificate System | =7.3 | |
Dogtag Certificate System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0588 is classified as a high severity vulnerability due to the ability for remote authenticated users to improperly approve certificate requests.
To fix CVE-2009-0588, users should upgrade to patched versions of Red Hat Certificate System 7.3 or Dogtag Certificate System that address the vulnerability.
CVE-2009-0588 affects users of Red Hat Certificate System 7.3 and Dogtag Certificate System where remote authenticated users have access.
CVE-2009-0588 involves the agent/request/op.cgi component in the Registration Authority of both Red Hat Certificate System and Dogtag Certificate System.
No, CVE-2009-0588 requires authentication, as it allows remote authenticated users to manipulate certificate requests.