CVE-2012-6137: Red Hat Enterprise Linux
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.
Affected products
- Red Hat Enterprise Linux: version 5 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Eus: version 5.9.z only
- Red Hat Enterprise Linux Hpc Node: version 6 only
- Red Hat Enterprise Linux Long Life: version 5.9 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 6.4 only
- Red Hat Enterprise Linux Server Eus: version 6.4.z only
- Red Hat Enterprise Linux Workstation: version 6.0 only
Published 2013-05-21. Last modified 2026-06-16.