CVE-2009-0588
Last modified
CVE-2009-0588 is a vulnerability of currently unknown severity. agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Certificate System | 7.3 |
| Redhat | Dogtag Certificate System | All versions |
References
- http://www.redhat.com/support/errata/RHSA-2009-1065.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1065.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0588?
How severe is CVE-2009-0588?
How do I fix CVE-2009-0588?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0582The ntlm_challenge function in the NTLM SASL authentication …
- CVE-2009-0583Multiple integer overflows in icc.c in the International Col…
- CVE-2009-0584icc.c in the International Color Consortium (ICC) Format lib…
- CVE-2009-0585Integer overflow in the soup_base64_encode function in soup-…
- CVE-2009-0586Integer overflow in the gst_vorbis_tag_add_coverart function…
- CVE-2009-0587Multiple integer overflows in Evolution Data Server (aka evo…
- CVE-2009-0589Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-0590The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k a…
- CVE-2009-0591The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, wh…
- CVE-2009-0592Multiple directory traversal vulnerabilities in PNphpBB2 1.2…
- CVE-2009-0593SQL injection vulnerability in members.php in plx Auto Remin…
- CVE-2009-0594Cross-site scripting (XSS) vulnerability in index.php in php…
Are you affected by CVE-2009-0588?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
