CVE-2012-0059
Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5.4 includes cleartext user passwords in an error message when a system registration XML-RPC call fails, which allows remote administrators to obtain the password by reading (1) the server log and (2) an email.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-209
- Published
- 2014-02-05
- Last modified
- 2026-04-03
Affected products
- n/a n/a
Weakness type
Related vulnerabilities
- CVE-2025-68110 — ChurchCRM discloses database information on error message
- CVE-2025-62168 — Squid vulnerable to information disclosure via authentication credential leakage in error handling
- CVE-2025-47813 — loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
- CVE-2026-33192 — free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
- CVE-2025-71282 — XenForo Path Disclosure via open_basedir Exceptions
- CVE-2024-11625 — Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affec
- CVE-2025-36003 — IBM Security Verify Governance Identity Manager information disclosure
- CVE-2025-23320 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c