CVE-2008-2368

medium

Description

Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.

References

https://rhn.redhat.com/errata/RHSA-2009-0007.html

https://rhn.redhat.com/errata/RHSA-2009-0006.html

https://exchange.xforce.ibmcloud.com/vulnerabilities/48022

https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-2364

https://bugzilla.redhat.com/show_bug.cgi?id=452000

http://www.vupen.com/english/advisories/2009/0145

http://www.securityfocus.com/bid/33288

http://securitytracker.com/id?1021608

http://secunia.com/advisories/33540

Details

Source: Mitre, NVD

Published: 2009-01-20

Updated: 2026-04-23

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00034