Vulnerability Name: | CVE-2012-6137 (CCN-84020) | ||||||||||||||||
Assigned: | 2012-12-06 | ||||||||||||||||
Published: | 2013-05-06 | ||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||
Summary: | rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-255 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-6137 Source: OSVDB Type: UNKNOWN 93058 Source: CCN Type: RHSA-2013:0788-1 Moderate: subscription-manager security update Source: REDHAT Type: Vendor Advisory RHSA-2013:0788 Source: SECUNIA Type: Vendor Advisory 53330 Source: CCN Type: Red Hat Web site Subscription Manager Source: BID Type: UNKNOWN 59674 Source: CCN Type: BID-59674 Red Hat Subscription Manager CVE-2012-6137 SSL Certificate Validation Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1028520 Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=885130 Source: XF Type: UNKNOWN redhat-ssl-cve20126137-sec-bypass(84020) Source: XF Type: UNKNOWN redhat-ssl-cve20126137-sec-bypass(84020) Source: CCN Type: WhiteSource Vulnerability Database CVE-2012-6137 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |