A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HFreeipa
APPFreeipa< 4.4.0Red Hat Enterprise Linux
OSRedhat7.0Red Hat Enterprise Linux Desktop
OSRedhat7.0Red Hat Enterprise Linux Server
OSRedhat7.0Red Hat Enterprise Linux Server Aus
OSRedhat7.37.4Red Hat Enterprise Linux Server Eus
OSRedhat7.37.47.5Red Hat Enterprise Linux Workstation
OSRedhat7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2019-5544CRITICAL9.8⚠ KEVPL ✓same product
Krytyczny heap overwrite w OpenSLP dla VMware ESXi i Horizon DaaS
CVE-2018-14667CRITICAL9.8⚠ KEVPL ✓same product
RCE przez EL injection w RichFaces Framework 3.X — brak uwierzytelnienia
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany