CVE-2012-5562
published 2019-12-02CVE-2012-5562: A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could…
PriorityP427medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
1.03%
59.6th percentile
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | < 5.6 | 5.6 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-782c-hpc8-pfgv: rhn-proxy: may transmit credentials over clear-text when accessing RHN Satellite
ghsa_unreviewed·2022-04-23
CVE-2012-5562 [LOW] CWE-319 GHSA-782c-hpc8-pfgv: rhn-proxy: may transmit credentials over clear-text when accessing RHN Satellite
rhn-proxy: may transmit credentials over clear-text when accessing RHN Satellite
Red Hat
CVE-2012-5562: A flaw was found in rhn-proxy
vendor_redhat·2019-12-02·CVSS 8.6
CVE-2012-5562 [HIGH] CWE-319 CVE-2012-5562: A flaw was found in rhn-proxy
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: satell
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2012-5562https://access.redhat.com/security/cve/cve-2012-5562https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5562https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-5562https://access.redhat.com/security/cve/cve-2012-5562https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5562https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-5562
2019-12-02
Published