← Vulnerability feed

Vulnerability record · CVE-2009-0588 · published 27 May 2009

CVE-2009-0588: Redhat certificate system vulnerability

Redhat · Certificate System

agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.

6.5 CVSS 2.0 Medium EPSS 1.3% · top 30.4%
6.5CVSS 2.0 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0588 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2021-20179Dogtagpki incorrect authorization vulnerabilityA flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …EPSS 1.2%7.5CVE-2013-1886Redhat certificate system vulnerabilityFormat string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System …EPSS 2.2%6.5CVE-2017-7509Redhat certificate system improper input validation vulnerabilityAn input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…EPSS 0.73%6.0CVE-2008-5082Redhat dogtag certificate system improper authentication vulnerabilityThe verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate S…EPSS 0.78%5.8CVE-2010-3868Redhat certificate system improper authentication vulnerabilityRed Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, w…EPSS 1.3%5.7CVE-2022-2393Pki-core project pki-core improper authorization vulnerabilityA flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.…EPSS 0.25%5.5CVE-2012-3367Redhat certificate system vulnerabilityRed Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the…EPSS 1.2%5.4CVE-2020-1696Redhat certificate system cross-site scripting vulnerabilityA flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a…EPSS 0.76%

Source: NIST National Vulnerability Database (record CVE-2009-0588), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.