CVE-2012-6137: Red Hat Enterprise Linux

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.

Affected products

  • Red Hat Enterprise Linux: version 5 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
  • Red Hat Enterprise Linux Eus: version 5.9.z only
  • Red Hat Enterprise Linux Hpc Node: version 6 only
  • Red Hat Enterprise Linux Long Life: version 5.9 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.4 only
  • Red Hat Enterprise Linux Server Eus: version 6.4.z only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2013-05-21. Last modified 2026-06-16.