CVE-2008-0893Redhat Directory Server vulnerability

CWE-2645 documents5 sources
Severity
7.5HIGHNVD
EPSS
1.4%
top 19.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 16
Latest updateMay 1

Description

Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-84ph-43p3-259x: Red Hat Administration Server, as used by Red Hat Directory Server 82022-05-01
CVEList
CVE-2008-0893: Red Hat Administration Server, as used by Red Hat Directory Server 82008-04-16

📋Vendor Advisories

1
Red Hat
Server: unrestricted access to CGI scripts2008-04-15

💬Community

1
Bugzilla
CVE-2008-0893 Directory Server: unrestricted access to CGI scripts2008-03-13
CVE-2008-0893 — Redhat Directory Server vulnerability | cvebase