
CVE-2017-7509 – 8: Enrolling certificate without certreq field causes CA to crash
https://notcve.org/view.php?id=CVE-2017-7509
30 Aug 2017 — An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate an assertion error is triggered causing a denial of service. Se ha detectado un error de validación de entradas en cómo gestiona Red Hat Certificate System los certificados proporcionados por el cliente en versiones anteriores a la 8.1.20-1. Si el campo certreq no está presente en un certificado, se desencadena un error de aserción... • http://www.securitytracker.com/id/1039248 • CWE-20: Improper Input Validation •

CVE-2013-1885 – System: pki-tps XSS flaw
https://notcve.org/view.php?id=CVE-2013-1885
23 May 2013 — Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/. Múltiples vulnerabilidades cross-site scripting (XSS) en el sistema de procesamiento de tokens (pki-tps) en Red Hat Certificate System (RHCS) 8.1 y posiblemente Dogtag Certificate System 9 y 10 permite a atacantes remotos... • http://osvdb.org/93626 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-1886 – System: pki-tps format string injection
https://notcve.org/view.php?id=CVE-2013-1886
23 May 2013 — Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates. Vulnerabilidad de formato de cadena de texto en el sistema de procesamiento de tokens (pki-tps) en Red Hat Certificate System (RHCS) 8.1 y posiblemente Dogtag Ce... • http://osvdb.org/93613 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-134: Use of Externally-Controlled Format String •

CVE-2012-4543 – System: Multiple cross-site scripting flaws by displaying CRL or processing profile
https://notcve.org/view.php?id=CVE-2012-4543
04 Jan 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en Red Hat Certificate System (RHCS) anteriores a v8.1.3, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de(... • http://rhn.redhat.com/errata/RHSA-2012-1550.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-4555 – pki-tps: Temporary denial of service on interrupted token format operations
https://notcve.org/view.php?id=CVE-2012-4555
04 Jan 2013 — The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child process crash) via unspecified vectors. El sistema de proceso de tokens (pki-tps) en Red Hat Certificate System (RHCS) anteriores a v8.1.3 no manejan de forma adecuada las interrupciones de las operaciones de formateo, lo que permite a at... • http://rhn.redhat.com/errata/RHSA-2012-1550.html •

CVE-2012-4556 – pki-tps: Connection reset when performing empty certificate search in TPS
https://notcve.org/view.php?id=CVE-2012-4556
04 Jan 2013 — The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query. El proceso de tokens en sistemas (pki-tps) en Red Hat Certificate System (RHCS) anteriores a v8.1.3 permite a atacantes remotos a provocar una denegación de servicio (reinicio del proceso hijo del servidor httpd del servidor Apache) a través d... • http://rhn.redhat.com/errata/RHSA-2012-1550.html • CWE-20: Improper Input Validation •

CVE-2012-3367 – System: CA certificate can be revoked
https://notcve.org/view.php?id=CVE-2012-3367
13 Aug 2012 — Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate. Red Hat Certificate System (RHCS) antes de v8.1.1 y Dogtag Certificate System no comprueban correctamente las solicitudes de revocación de certificados realizadas a través de la interfaz web, lo que permite revoc... • http://osvdb.org/84098 • CWE-310: Cryptographic Issues •

CVE-2012-2662 – System: multiple XSS flaws
https://notcve.org/view.php?id=CVE-2012-2662
13 Aug 2012 — Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages. Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en Red Hat Certificate System (RHCS) antes de v8.1.1 y Dogtag Certificate System permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de ... • http://osvdb.org/84099 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2010-3868 – System: unauthenticated user can request SCEP one-time PIN decryption
https://notcve.org/view.php?id=CVE-2010-3868
17 Nov 2010 — Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component. Red Hat Certificate System (RHCS) v7.3 y v8 y Dogtag Certificate System no requieren autenticación en peticiones para descifrar PINs SCEP one-time, lo que permite a atacantes remotos la obtención de P... • http://secunia.com/advisories/42181 • CWE-287: Improper Authentication •

CVE-2010-3869 – System: SCEP one-time PIN reuse
https://notcve.org/view.php?id=CVE-2010-3869
17 Nov 2010 — Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN. Red Hat Certificate System (RHCS) v7.3 y v8 y Dogtag Certificate System permiten a usuarios autenticados remotamente generar un número aleatorio de certificados mediante la sustitución de un único PIN SCEP one-time. • http://secunia.com/advisories/42181 • CWE-310: Cryptographic Issues •