CVE Vulnerabilities

CVE-2012-6137

Published: May 21, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic servers X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linuxRedhat5 (including)5 (including)
Enterprise_linux_desktopRedhat5.0 (including)5.0 (including)
Enterprise_linux_desktopRedhat6.0 (including)6.0 (including)
Enterprise_linux_eusRedhat5.9.z (including)5.9.z (including)
Enterprise_linux_hpc_nodeRedhat6 (including)6 (including)
Enterprise_linux_long_lifeRedhat5.9 (including)5.9 (including)
Enterprise_linux_serverRedhat6.0 (including)6.0 (including)
Enterprise_linux_server_ausRedhat6.4 (including)6.4 (including)
Enterprise_linux_server_eusRedhat6.4.z (including)6.4.z (including)
Enterprise_linux_workstationRedhat6.0 (including)6.0 (including)
Red Hat Enterprise Linux 5RedHatsubscription-manager-0:1.0.24.1-1.el5_9*
Red Hat Enterprise Linux 6RedHatsubscription-manager-0:1.1.23.1-1.el6_4*

References