MEDIUM · 6.5

CVE-2008-2139

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it e...

Vulnerability Description

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.

CVSS Score

6.5

MEDIUM

AV:A/AC:H/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
RpathAppliance Platform Agent2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2139?

CVE-2008-2139 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it e...

How severe is CVE-2008-2139?

CVE-2008-2139 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2139?

Check the references section above for vendor advisories and patch information. Affected products include: Rpath Appliance Platform Agent.