In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
Metrics
Affected Vendors & Products
References
History
Tue, 27 Aug 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat enterprise Linux
|
|
CPEs | cpe:/a:redhat:enterprise_linux:5::hypervisor | |
Vendors & Products |
Redhat enterprise Linux
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2019-11-09T02:32:02
Updated: 2024-08-07T06:31:10.393Z
Reserved: 2009-10-05T00:00:00
Link: CVE-2009-3552
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-11-09T03:15:10.307
Modified: 2024-11-21T01:07:38.540
Link: CVE-2009-3552
Redhat