CVE-2012-0059
Last modified
CVE-2012-0059 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. EPSS estimates a 1.64% chance of exploitation in the next 30 days.
Description
A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Network Proxy | 5.4 |
| Redhat | Satellite | 5.4 |
References
- http://rhn.redhat.com/errata/RHSA-2012-0101.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0102.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0101.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0102.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0059?
How severe is CVE-2012-0059?
How do I fix CVE-2012-0059?
Are you affected by CVE-2012-0059?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
