7.8
CVSSv3

CVE-2023-3899

Published: 23/08/2023 Updated: 09/11/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an malicious user to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat subscription-manager

fedoraproject fedora 37

fedoraproject fedora 38

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux for scientific computing 7.0

redhat enterprise linux server 7.0

redhat enterprise linux for power little endian 7.0

redhat enterprise linux for power big endian 7.0

redhat enterprise linux for ibm z systems 7.0

redhat enterprise linux 8.0

redhat enterprise linux server tus 8.2

redhat enterprise linux server aus 8.2

redhat enterprise linux server tus 8.4

redhat enterprise linux server aus 8.4

redhat enterprise linux for power little endian 8.0

redhat enterprise linux for ibm z systems 8.0

redhat enterprise linux server for power little endian update services for sap solutions 8.1

redhat enterprise linux server for power little endian update services for sap solutions 8.2

redhat enterprise linux server for power little endian update services for sap solutions 8.4

redhat enterprise linux server for power little endian update services for sap solutions 8.6

redhat enterprise linux for ibm z systems eus 8.6

redhat enterprise linux server aus 8.6

redhat enterprise linux server tus 8.6

redhat enterprise linux eus 8.6

redhat enterprise linux 9.0

redhat enterprise linux server for power little endian update services for sap solutions 9.0

redhat enterprise linux for power little endian eus 9.0

redhat enterprise linux for power little endian 9.0

redhat enterprise linux eus 9.0

redhat enterprise linux server update services for sap solutions 9.0

redhat enterprise linux for ibm z systems 9.0

redhat enterprise linux for ibm z systems eus 9.0

redhat enterprise linux server tus 8.8

redhat enterprise linux eus 8.8

redhat enterprise linux server aus 9.2

redhat enterprise linux eus 9.2

redhat enterprise linux for ibm z systems eus 9.2

redhat enterprise linux for power little endian eus 9.2

redhat enterprise linux for arm 64 9.0

redhat enterprise linux for arm 64 eus 9.2

redhat enterprise linux for arm 64 9.2

redhat enterprise linux server update services for sap solutions 9.2

redhat enterprise linux server for power little endian update services for sap solutions 9.2

redhat enterprise linux for arm 64 eus 8.6

redhat enterprise linux for arm 64 eus 8.8

redhat enterprise linux for arm 64 8.0

redhat enterprise linux for arm 64 eus 9.0

redhat enterprise linux for ibm z systems eus 8.8

redhat enterprise linux for ibm z systems 9.2

redhat enterprise linux server for power little endian update services for sap solutions 8.8

redhat enterprise linux for power little endian eus 8.8

redhat enterprise linux update services for sap solutions 8.4

redhat enterprise linux update services for sap solutions 8.1

redhat enterprise linux update services for sap solutions 8.2

redhat enterprise linux update services for sap solutions 8.6

redhat enterprise linux update services for sap solutions 8.8

Vendor Advisories

Description<!---->A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization The D-Bus interface comredhatRHSM1 exposes a significant number of methods to all users that could change the state of the registration By using the comredhatRHSM1ConfigSetAll() method, a low-privileged ...
Synopsis Important: subscription-manager security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 84 Advanced Mission Critical Updat ...
Synopsis Important: subscription-manager security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 82 Advanced Update Support, Red Ha ...
Synopsis Moderate: OpenShift Container Platform 41310 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41310 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Pla ...
Synopsis Moderate: Multicluster Engine for Kubernetes 232 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Multicluster Engine for Kubernetes 232 General Availability release images,which contain security updates and fix bugsRed Hat Product Security has rated this update as having a security impactof Moderat ...
Synopsis Important: Migration Toolkit for Containers (MTC) 180 security and bug fix update Type/Severity Security Advisory: Important Topic The Migration Toolkit for Containers (MTC) 180 is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Moderate: subscription-manager security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated ...
Synopsis Moderate: OpenShift Container Platform 41310 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41310 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Pla ...
Synopsis Important: Migration Toolkit for Applications security update Type/Severity Security Advisory: Important Topic An update is now available for MTA-61-RHEL-8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity ...
Synopsis Important: Red Hat OpenShift Data Foundation 4133 security and bug fix update Type/Severity Security Advisory: Important Topic Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4133 on Red Hat Enterprise Linux 8 from Red Hat Container RegistryRed Hat Product Security has rated this upda ...
Synopsis Moderate: Migration Toolkit for Containers (MTC) 1713 security and bug fix update Type/Severity Security Advisory: Moderate Topic The Migration Toolkit for Containers (MTC) 1713 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: RHACS 41 enhancement and security update Type/Severity Security Advisory: Important Topic Updated images are now available for Red Hat Advanced Cluster Security (RHACS) The updated image includes new features and bug fixesRed Hat Product Security has rated this update as having a security impact of Important A Common V ...
Synopsis Important: Service Telemetry Framework 152 security update Type/Severity Security Advisory: Important Topic An update is now available for Service Telemetry Framework 152Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Important: Self Node Remediation Operator 051 security update Type/Severity Security Advisory: Important Topic This is an updated version of the Self Node Remediation Operator This Operator is delivered by Red Hat Workload AvailabilityRed Hat Product Security has rated this update as having a security impact of Important A Commo ...
Synopsis Important: Node Health Check Operator 041 Type/Severity Security Advisory: Important Topic This is an updated version of the Node Health Check Operator This Operator is delivered by Red Hat Workload AvailabilityRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...
Synopsis Critical: Red Hat Advanced Cluster Management 267 security and bug fix updates Type/Severity Security Advisory: Critical Topic Red Hat Advanced Cluster Management for Kubernetes 267 GeneralAvailability release images, which provide security updates and fix bugsRed Hat Product Security has rated this update as having a security i ...
Synopsis Moderate: OpenShift Virtualization 4126 Images Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Virtualization release 4126 is now available with updates to packages and images that fix several bugs and add enhancements Description OpenShift Virtualization is Red Hat's virtualization solution designed for Red ...
Synopsis Critical: Red Hat OpenShift GitOps security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift GitOps 19Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity ...
Synopsis Important: subscription-manager security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 81 Update Services for SAP Solutio ...
Synopsis Important: Red Hat OpenShift Pipelines Operator security update Type/Severity Security Advisory: Important Topic An update is now available for OpenShift-Pipelines-111-RHEL-8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Important: Self Node Remediation Operator 071 security update Type/Severity Security Advisory: Important Topic This is an updated version of the Self Node Remediation Operator This Operator is delivered by Red Hat Workload AvailabilityRed Hat Product Security has rated this update as having a security impact of Important A Commo ...
Synopsis Important: subscription-manager security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rate ...
Synopsis Important: subscription-manager security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat ...
Synopsis Important: subscription-manager security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rate ...
Synopsis Important: subscription-manager security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for subscription-manager is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat ...
Synopsis Important: Red Hat OpenShift Pipelines 1106 release and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Pipelines 1106 has been releasedRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a ...