CVE-2009-0588
Summary
| CVE | CVE-2009-0588 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-27 16:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field. |
Risk And Classification
Primary CVSS: v2.0 6.5 from [email protected]
AV:N/AC:L/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Certificate System | 7.3 | All | All | All |
| Application | Redhat | Dogtag Certificate System | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat update for rhpki-ra - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch, Vendor Advisory |
| 488706 – (CVE-2009-0588) CVE-2009-0588 rhpki-ra: improper authorization checks in Cerificate System's Registration Authority | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Red Hat Certificate System 'agent/request/op.cgi' Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Dogtag Certificate System Agent Group Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 484828 – op.cgi security bug allows RA agents to approve requests not assigned to their agent group | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| Red Hat Certificate System Bug in Registration Authority Lets Remote Authenticated Users Bypass Access Controls - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.