CVE-2008-2139
Last modified
CVE-2008-2139 is a vulnerability of currently unknown severity. The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rpath | Appliance Platform Agent | 2 |
| Rpath | Appliance Platform Agent | 3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2139?
How severe is CVE-2008-2139?
How do I fix CVE-2008-2139?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2133Cross-site scripting (XSS) vulnerability in the Journal modu…
- CVE-2008-2134The Journal module in Tru-Zone Nuke ET 3.x allows remote att…
- CVE-2008-2135Multiple SQL injection vulnerabilities in VisualShapers ezCo…
- CVE-2008-2136Memory leak in the ipip6_rcv function in net/ipv6/sit.c in t…
- CVE-2008-2137The (1) sparc_mmap_check function in arch/sparc/kernel/sys_s…
- CVE-2008-2138Oracle Application Server (OracleAS) Portal 10g allows remot…
- CVE-2008-2140Cross-site request forgery (CSRF) vulnerability in the rootp…
- CVE-2008-2142Emacs 21 and XEmacs automatically load and execute .flc (fas…
- CVE-2008-2143Unspecified versions of Microsoft Outlook Web Access (OWA) u…
- CVE-2008-2144Multiple unspecified vulnerabilities in Solaris print servic…
- CVE-2008-2145Stack-based buffer overflow in Novell Client 4.91 SP4 and ea…
- CVE-2008-2146wp-includes/vars.php in Wordpress before 2.2.3 does not prop…
Are you affected by CVE-2008-2139?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
