CVE Vulnerabilities

CVE-2012-5562

Cleartext Transmission of Sensitive Information

Published: Dec 02, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.8 MODERATE
AV:A/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu

rhn-proxy: may transmit credentials over clear-text when accessing RHN Satellite

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Satellite Redhat * 5.6 (excluding)
Red Hat Satellite Proxy v 5.6 RedHat eventReceivers-0:2.20.18-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat gc-0:7.1-8.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat jabberd-0:2.2.8-22.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat jabberd-selinux-0:2.0.1-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat libapreq2-0:2.13-5.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat libgsasl-0:1.4.0-5.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat libntlm-0:1.0-4.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat MessageQueue-0:3.26.9-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat mod_wsgi-0:3.2-3.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat nocpulse-common-0:2.2.7-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat nocpulse-db-perl-0:3.6.5-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat NOCpulsePlugins-0:2.209.6-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat NPalert-0:1.127.12-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat oracle-config-0:1.1-7.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat oracle-instantclient-0:10.2.0-47.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat oracle-instantclient-selinux-0:10.2.0.19-5.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat oracle-selinux-0:0.1.23.35-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-BerkeleyDB-0:0.38-6.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Class-MethodMaker-0:1.12-12.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-Class-Singleton-0:1.4-6.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Config-IniFiles-0:2.47-5.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Convert-BinHex-0:1.119-10.1.el6 *
Red Hat Satellite Proxy v 5.6 RedHat perl-Crypt-DES-0:2.05-10.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Crypt-GeneratePassword-0:0.03-15.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-DateTime-0:0.27-10.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-DateTime-Locale-0:0.09-14.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-DateTime-TimeZone-0:0.59-8.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-DBD-Oracle-0:1.62-2.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Email-Date-Format-0:1.002-5.el6 *
Red Hat Satellite Proxy v 5.6 RedHat perl-Error-0:0.15-7.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-FreezeThaw-0:0.43-14.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-HTML-TableExtract-0:2.10-8.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-IO-stringy-0:2.110-10.1.el6 *
Red Hat Satellite Proxy v 5.6 RedHat perl-List-MoreUtils-0:0.22-10.el6 *
Red Hat Satellite Proxy v 5.6 RedHat perl-MailTools-0:1.66-6.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-MIME-Lite-0:3.01-6.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-MIME-tools-0:5.411a-12.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-MIME-Types-0:1.28-2.el6 *
Red Hat Satellite Proxy v 5.6 RedHat perl-Net-IPv4Addr-0:0.10-7.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Net-LibIDN-0:0.12-3.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Net-SNMP-0:4.0.3-10.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-CLAC-0:1.9.9-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-Debug-0:1.23.17-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-Gritch-0:1.27.11-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-Object-0:1.26.12-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-OracleDB-0:1.28.27-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-PersistentConnection-0:1.10.1-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-Probe-0:1.184.17-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-ProcessPool-0:1.6.1-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-Scheduler-0:1.58.12-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-SetID-0:1.7.1-3.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-NOCpulse-Utils-0:1.14.12-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-Params-Validate-0:0.92-3.el6 *
Red Hat Satellite Proxy v 5.6 RedHat perl-SOAP-Lite-0:0.60a-11.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-XML-DOM-0:1.44-1.el5 *
Red Hat Satellite Proxy v 5.6 RedHat perl-XML-Generator-0:1.01-6.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat perl-XML-RegExp-0:0.03-2.el5 *
Red Hat Satellite Proxy v 5.6 RedHat ProgAGoGo-0:1.11.6-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat python-debian-0:0.1.16-5.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat python-hashlib-0:20081119-6.el5 *
Red Hat Satellite Proxy v 5.6 RedHat rhnlib-0:2.5.22-15.el6 *
Red Hat Satellite Proxy v 5.6 RedHat rhnpush-0:5.5.65-5.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat SatConfig-bootstrap-0:1.11.5-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat SatConfig-bootstrap-server-0:1.13.5-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat SatConfig-cluster-0:1.54.10-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat SatConfig-general-0:1.216.29-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat SatConfig-generator-0:2.29.14-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat SatConfig-installer-0:3.24.6-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat SatConfig-spread-0:1.1.3-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat satellite-branding-0:5.6.0.22-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat scdb-0:1.15.8-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat SNMPAlerts-0:0.5.7-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-backend-0:2.0.3-18.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-certs-tools-0:2.0.1-2.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-monitoring-selinux-0:2.0.1-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-proxy-0:2.0.1-8.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-proxy-docs-0:2.0.1-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-proxy-monitoring-0:2.0.1-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-proxy-selinux-0:2.0.1-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-setup-jabberd-0:2.0.1-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-ssl-cert-check-1:2.3-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat spacewalk-web-0:2.0.3-17.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat SputLite-0:1.10.1-1.el6sat *
Red Hat Satellite Proxy v 5.6 RedHat ssl_bridge-0:1.9.3-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat status_log_acceptor-0:0.12.11-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat tsdb-0:1.27.29-1.el5sat *
Red Hat Satellite Proxy v 5.6 RedHat udns-0:0.1-1.el5sat *

Potential Mitigations

References