← Back

CVE-2008-2139

nvd nist
Published: May 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.5
Vector
AV:A/AC:H/Au:S/C:C/I:C/A:C
Exploitability: 2.5 / Impact: 10.0
Source: NVD

Description

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.

Affected (2)

1 product
Appliance Platform Agent
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Rpath
Version 2
Version 3

Related CWEs

Timeline

No history available yet.