CVE-2008-2368

N/A Unknown
Published: January 20, 2009 Modified: April 23, 2026
View on NVD

Description

Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/33540
Source: secalert@redhat.com
Vendor Advisory
http://securitytracker.com/id?1021608
Source: secalert@redhat.com
http://www.securityfocus.com/bid/33288
Source: secalert@redhat.com
https://rhn.redhat.com/errata/RHSA-2009-0006.html
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/33540
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securitytracker.com/id?1021608
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/33288
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2009/0145
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=452000
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/48022
Source: af854a3a-2127-422b-91ae-364da2661108
https://rhn.redhat.com/errata/RHSA-2009-0006.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://rhn.redhat.com/errata/RHSA-2009-0007.html
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.0%
10th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

redhat