CVE-2016-9575
Dashboard / Vulnerabilities / CVE-2016-9575
CVE-2016-9575
Published: 13 Mar 2018Last Modified: 8 Jul 2026
Summary:
Details: Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.
References: http://rhn.redhat.com/errata/RHSA-2017-0001.html, http://www.securityfocus.com/bid/95068, https://bugzilla.redhat.com/show_bug.cgi?id=1395311
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 218de5bff792f5ac40d9b3eebc22f19696e5091e
Fixed -None
Affected versions
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
