CVE-2012-3367
Summary
| CVE | CVE-2012-3367 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-13 20:55:08 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Certificate System | 7.1 | All | All | All |
| Application | Redhat | Certificate System | 7.2 | All | All | All |
| Application | Redhat | Certificate System | 7.3 | All | All | All |
| Application | Redhat | Certificate System | 8 | All | All | All |
| Application | Redhat | Certificate System | 8.0 | All | All | All |
| Application | Redhat | Certificate System | All | All | All | All |
| Application | Redhat | Dogtag Certificate System | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 836268 – (CVE-2012-3367) CVE-2012-3367 Certificate System: CA certificate can be revoked | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/84098 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Overview - dogtagpki - Pagure.io | af854a3a-2127-422b-91ae-364da2661108 | fedorahosted.org | Exploit, Patch |
| Security Advisory SA50013 - Red Hat Certificate System Cross-Site Scripting and Security Bypass Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Certificate System Multiple Cross Site Scripting and Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Red Hat Certificate System Bugs Let Remote Users Conduct Cross-Site Scripting and Denial of Service Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.