Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2016-9575

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.
0
Attacker Value
Unknown

CVE-2017-11191

Disclosure Date: September 28, 2017 (last updated November 08, 2023)
FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern
0
Attacker Value
Unknown

CVE-2016-5414

Disclosure Date: June 27, 2017 (last updated November 26, 2024)
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
0