cbcvebase.
CVE-2016-9575
published 2018-03-13

CVE-2016-9575: Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's…

PriorityP434medium6.3CVSS 3.0
AVNACLPRLUINSUCLILAL
EPSS
0.79%
52.0th percentile
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianfreeipa< freeipa 4.4.4-1 (bookworm)freeipa 4.4.4-1 (bookworm)
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa
freeipafreeipa>= 0 < 4.4.4-14.4.4-1
freeipafreeipa>= 0 < 4.4.4-14.4.4-1
freeipafreeipa>= 0 < 4.4.4-14.4.4-1
freeipafreeipa>= 0 < 3.3.4-0ubuntu3.1+esm13.3.4-0ubuntu3.1+esm1
freeipafreeipa>= 0 < 4.3.1-0ubuntu1+esm14.3.1-0ubuntu1+esm1
freeipaipa
freeipaipa
freeipaipa

CVSS provenance

nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.