CVE Vulnerabilities

CVE-2008-2139

Published: May 12, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:A/AC:H/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.

Affected Software

NameVendorStart VersionEnd Version
Appliance_platform_agentRpath2 (including)2 (including)
Appliance_platform_agentRpath3 (including)3 (including)

References