Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:redhat:certificate_system:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE009B1B-E0AB-4BA4-9A18-5F2A45FDCB7F", "versionEndIncluding": "8.1", "vulnerable": true}, {"criteria": "cpe:2.3:a:redhat:certificate_system:7.1:*:*:*:*:*:*:*", "matchCriteriaId": "A94B7103-11B7-4B1E-AE02-86210F9CCCAA", "vulnerable": true}, {"criteria": "cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:*", "matchCriteriaId": "27FE079E-FB15-443C-BE2E-1D4C940BB8C0", "vulnerable": true}, {"criteria": "cpe:2.3:a:redhat:certificate_system:7.3:*:*:*:*:*:*:*", "matchCriteriaId": "E2654E6A-190C-4D5C-ABC0-89011DD8E293", "vulnerable": true}, {"criteria": "cpe:2.3:a:redhat:certificate_system:8:*:*:*:*:*:*:*", "matchCriteriaId": "C2EF75FF-FCDB-433C-A7B9-4DBAABAC6643", "vulnerable": true}, {"criteria": "cpe:2.3:a:redhat:certificate_system:8.0:*:*:*:*:*:*:*", "matchCriteriaId": "969F1FDC-EB66-4758-B619-C48CA1E5B1AC", "vulnerable": true}, {"criteria": "cpe:2.3:a:redhat:dogtag_certificate_system:*:*:*:*:*:*:*:*", "matchCriteriaId": "06D606EF-447B-42C5-ADBE-14515257262B", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate."}, {"lang": "es", "value": "Red Hat Certificate System (RHCS) antes de v8.1.1 y Dogtag Certificate System no comprueban correctamente las solicitudes de revocaci\u00f3n de certificados realizadas a trav\u00e9s de la interfaz web, lo que permite revocar los certificados finales de entidad que revocan certificados de autoridad de certificaci\u00f3n (CA) a atacantes remotos con permisos.\r\n"}], "id": "CVE-2012-3367", "lastModified": "2024-11-21T01:40:43.213", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 5.5, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 8.0, "impactScore": 4.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2012-08-13T20:55:08.397", "references": [{"source": "secalert@redhat.com", "url": "http://osvdb.org/84098"}, {"source": "secalert@redhat.com", "url": "http://rhn.redhat.com/errata/RHSA-2012-1103.html"}, {"source": "secalert@redhat.com", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/50013"}, {"source": "secalert@redhat.com", "url": "http://www.securityfocus.com/bid/54608"}, {"source": "secalert@redhat.com", "url": "http://www.securitytracker.com/id?1027284"}, {"source": "secalert@redhat.com", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=836268"}, {"source": "secalert@redhat.com", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77102"}, {"source": "secalert@redhat.com", "tags": ["Exploit", "Patch"], "url": "https://fedorahosted.org/pki/changeset/2430"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://osvdb.org/84098"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://rhn.redhat.com/errata/RHSA-2012-1103.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/50013"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/54608"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id?1027284"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=836268"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77102"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Patch"], "url": "https://fedorahosted.org/pki/changeset/2430"}], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-310"}], "source": "nvd@nist.gov", "type": "Primary"}]}