Vulnerability Description
rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 5 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Eus | 5.9.z |
| Redhat | Enterprise Linux Hpc Node | 6 |
| Redhat | Enterprise Linux Long Life | 5.9 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server Aus | 6.4 |
| Redhat | Enterprise Linux Server Eus | 6.4.z |
| Redhat | Enterprise Linux Workstation | 6.0 |
Related Weaknesses (CWE)
References
- http://osvdb.org/93058
- http://rhn.redhat.com/errata/RHSA-2013-0788.htmlVendor Advisory
- http://secunia.com/advisories/53330Vendor Advisory
- http://www.securityfocus.com/bid/59674
- http://www.securitytracker.com/id/1028520
- https://bugzilla.redhat.com/show_bug.cgi?id=885130
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84020
- http://osvdb.org/93058
- http://rhn.redhat.com/errata/RHSA-2013-0788.htmlVendor Advisory
- http://secunia.com/advisories/53330Vendor Advisory
- http://www.securityfocus.com/bid/59674
- http://www.securitytracker.com/id/1028520
- https://bugzilla.redhat.com/show_bug.cgi?id=885130
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84020
FAQ
What is CVE-2012-6137?
CVE-2012-6137 is a vulnerability with a CVSS score of 4.3 (MEDIUM). rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which all...
How severe is CVE-2012-6137?
CVE-2012-6137 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-6137?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Hpc Node, Redhat Enterprise Linux Long Life.