{"api_version":"1","generated_at":"2026-07-23T18:58:14+00:00","cve":"CVE-2009-0588","urls":{"html":"https://cve.report/CVE-2009-0588","api":"https://cve.report/api/cve/CVE-2009-0588.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0588","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0588"},"summary":{"title":"CVE-2009-0588","description":"agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.","state":"PUBLISHED","assigner":"redhat","published_at":"2009-05-27 16:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/35263","name":"http://secunia.com/advisories/35263","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat update for rhpki-ra - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2009-1065.html","name":"http://www.redhat.com/support/errata/RHSA-2009-1065.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Support | Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=488706","name":"https://bugzilla.redhat.com/show_bug.cgi?id=488706","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"488706 – (CVE-2009-0588) CVE-2009-0588 rhpki-ra: improper authorization checks in Cerificate System's Registration Authority","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35104","name":"http://www.securityfocus.com/bid/35104","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Certificate System 'agent/request/op.cgi' Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/35242","name":"http://secunia.com/advisories/35242","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Dogtag Certificate System Agent Group Security Bypass - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=484828","name":"https://bugzilla.redhat.com/show_bug.cgi?id=484828","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"484828 – op.cgi security bug allows RA agents to approve requests not assigned to their agent group","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022278","name":"http://www.securitytracker.com/id?1022278","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Certificate System Bug in Registration Authority Lets Remote Authenticated Users Bypass Access Controls - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0588","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0588","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"588","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"certificate_system","cpe6":"7.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"588","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"dogtag_certificate_system","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:40:05.106Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=488706"},{"name":"35263","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35263"},{"name":"1022278","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022278"},{"name":"35104","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35104"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=484828"},{"name":"RHSA-2009:1065","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1065.html"},{"name":"35242","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35242"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-05-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-06-09T09:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=488706"},{"name":"35263","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35263"},{"name":"1022278","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022278"},{"name":"35104","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35104"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=484828"},{"name":"RHSA-2009:1065","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1065.html"},{"name":"35242","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35242"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2009-0588","datePublished":"2009-05-27T16:00:00.000Z","dateReserved":"2009-02-13T00:00:00.000Z","dateUpdated":"2024-08-07T04:40:05.106Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-27 16:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:*","matchCriteriaId":"E2654E6A-190C-4D5C-ABC0-89011DD8E293"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:dogtag_certificate_system:*:*:*:*:*:*:*:*","matchCriteriaId":"06D606EF-447B-42C5-ADBE-14515257262B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"588","Ordinal":"1","Title":"CVE-2009-0588","CVE":"CVE-2009-0588","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"588","Ordinal":"1","NoteData":"agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.","Type":"Description","Title":"CVE-2009-0588"},{"CveYear":"2009","CveId":"588","Ordinal":"2","NoteData":"2009-05-27","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"588","Ordinal":"3","NoteData":"2009-06-09","Type":"Other","Title":"Modified"}]}}}