CVE Vulnerabilities

CVE-2012-0059

Published: Feb 05, 2014 | Modified: Feb 03, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5.4 includes cleartext user passwords in an error message when a system registration XML-RPC call fails, which allows remote administrators to obtain the password by reading (1) the server log and (2) an email.

Affected Software

Name Vendor Start Version End Version
Network_proxy Redhat 5.4 (including) 5.4 (including)
Satellite Redhat 5.4 (including) 5.4 (including)
Red Hat Network Proxy v 5.4 RedHat spacewalk-backend-0:1.2.13-66.el5sat *
Red Hat Network Satellite Server v 5.4 RedHat spacewalk-backend-0:1.2.13-66.el5sat *

References