CVE Vulnerabilities

CVE-2008-2139

Published: May 12, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:A/AC:H/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.

Affected Software

Name Vendor Start Version End Version
Appliance_platform_agent Rpath 2 (including) 2 (including)
Appliance_platform_agent Rpath 3 (including) 3 (including)

References