REDHAT-BUG-488706: Medium severity Red Hat Certificate System vulnerability

Published Mar 5, 2009
·
Updated

Robert Mead reported that the Registration Authority component (rhpki-ra) of the Red Hat Certificate System / Dogtag Certificate System did not properly check agent's authorizations in some CGI scripts.

In deployments, where certificate requests are processed by multiple agent groups, agent from any group was able to approve or reject certificate requests in the queue for any other agent group, if he was able to guess request ID.

Original report: bug #484828

Affected systems: Dogtag Certificate System Red Hat Certificate System 7.3

Affected Software

2 affected components
Red Hat Certificate System
Red Hat Dogtag Certificate System

Event History

Mar 5, 2009
Data Sourced
11:19 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-488706?

REDHAT-BUG-488706 is classified as a medium severity vulnerability due to improper authorization checks.

2

How do I fix REDHAT-BUG-488706?

To mitigate REDHAT-BUG-488706, you should update to the latest version of the affected Red Hat Certificate System or Dogtag Certificate System as per Red Hat's security advisories.

3

What components are affected by REDHAT-BUG-488706?

The vulnerability affects the Registration Authority component of the Red Hat Certificate System and Dogtag Certificate System.

4

Can REDHAT-BUG-488706 lead to unauthorized access?

Yes, REDHAT-BUG-488706 can potentially allow unauthorized actions due to the lack of proper authorization checks in CGI scripts.

5

Who reported the REDHAT-BUG-488706 vulnerability?

The REDHAT-BUG-488706 vulnerability was reported by Robert Mead.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203