Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.
https://exchange.xforce.ibmcloud.com/vulnerabilities/42393
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0148
Source: Mitre, NVD
Published: 2008-05-12
Updated: 2026-06-16
Base Score: 2.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N
Severity: Low
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.00114