CVE-2012-0059

A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:network_proxy:5.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:5.4:*:*:*:*:*:*:*

History

03 Apr 2026, 00:16

Type Values Removed Values Added
CVSS v2 : 4.3
v3 : unknown
v2 : 4.3
v3 : 4.9
CWE CWE-209
Summary (en) Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5.4 includes cleartext user passwords in an error message when a system registration XML-RPC call fails, which allows remote administrators to obtain the password by reading (1) the server log and (2) an email. (en) A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.
References
  • () https://access.redhat.com/security/cve/CVE-2012-0059 -

21 Nov 2024, 01:34

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2012-0101.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2012-0101.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2012-0102.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2012-0102.html - Vendor Advisory

Information

Published : 2014-02-05 18:55

Updated : 2026-04-29 01:13


NVD link : CVE-2012-0059

Mitre link : CVE-2012-0059

CVE.ORG link : CVE-2012-0059


JSON object : View

Products Affected

redhat

  • network_proxy
  • satellite
CWE
CWE-209

Generation of Error Message Containing Sensitive Information

CWE-310

Cryptographic Issues