4.3
CVSSv2

CVE-2012-6137

Published: 21/05/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle malicious users to obtain sensitive information such as user credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 5

redhat enterprise linux server aus 6.4

redhat enterprise linux server eus 6.4.z

redhat enterprise linux long life 5.9

redhat enterprise linux server 6.0

redhat enterprise linux eus 5.9.z

redhat enterprise linux hpc node 6

redhat enterprise linux desktop 5.0

redhat enterprise linux desktop 6.0

redhat enterprise linux workstation 6.0

Vendor Advisories

Synopsis Moderate: subscription-manager security update Type/Severity Security Advisory: Moderate Topic Updated subscription-manager packages that fix one security issue are nowavailable for Red Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having moderatesecurity ...
rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials ...