9.3
CVSSv2

CVE-2013-6439

Published: 23/12/2013 Updated: 13/02/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Candlepin in Red Hat Subscription Asset Manager 1.0 up to and including 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat subscription asset manager 1.1.0

redhat subscription asset manager 1.0.0

redhat subscription asset manager 1.2.0

redhat subscription asset manager 1.2.1

redhat subscription asset manager 1.3.0

Vendor Advisories

Synopsis Important: candlepin security update Type/Severity Security Advisory: Important Topic Updated candlepin packages that fix one security issue are now availablefor Red Hat Subscription Asset ManagerThe Red Hat Security Response Team has rated this update as havingimportant security impact A Common ...
Candlepin in Red Hat Subscription Asset Manager 10 through 13 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors ...