First published: Mon Aug 13 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Certificate System | <=8.1 | |
Red Hat Certificate System | =7.1 | |
Red Hat Certificate System | =7.2 | |
Red Hat Certificate System | =7.3 | |
Red Hat Certificate System | =8 | |
Red Hat Certificate System | =8.0 | |
Dogtag Certificate System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2662 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2012-2662, upgrade to Red Hat Certificate System version 8.1.1 or later, or apply the recommended patches from Red Hat.
CVE-2012-2662 affects multiple versions of the Red Hat Certificate System and Dogtag Certificate System, specifically versions before 8.1.1.
Yes, CVE-2012-2662 allows remote attackers to inject arbitrary web script or HTML, potentially compromising user security.
Exploiting CVE-2012-2662 can lead to unauthorized actions being performed on behalf of users, including data theft and session hijacking.