Security Advisory

CVE-2016-9575

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-13 13:00:00
Last updated 2024-09-16 22:51:45
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.