Логотип exploitDog
bind:"CVE-2025-7493"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-7493"

Количество 8

Количество 8

ubuntu логотип

CVE-2025-7493

16 дней назад

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2025-7493

16 дней назад

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2025-7493

16 дней назад

A privilege escalation flaw from host to domain administrator was foun ...

CVSS3: 9.1
EPSS: Низкий
rocky логотип

RLSA-2025:17085

9 дней назад

Important: ipa security update

EPSS: Низкий
github логотип

GHSA-vm59-52f9-r52r

16 дней назад

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
EPSS: Низкий
oracle-oval логотип

ELSA-2025-17129

16 дней назад

ELSA-2025-17129: idm:DL1 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-17085

15 дней назад

ELSA-2025-17085: ipa security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-17084

16 дней назад

ELSA-2025-17084: ipa security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-7493

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2025-7493

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
0%
Низкий
16 дней назад
debian логотип
CVE-2025-7493

A privilege escalation flaw from host to domain administrator was foun ...

CVSS3: 9.1
0%
Низкий
16 дней назад
rocky логотип
RLSA-2025:17085

Important: ipa security update

0%
Низкий
9 дней назад
github логотип
GHSA-vm59-52f9-r52r

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the uniqueness of the krbCanonicalName. While the previously released version added validations for the admin@REALM credential, FreeIPA still does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

CVSS3: 9.1
0%
Низкий
16 дней назад
oracle-oval логотип
ELSA-2025-17129

ELSA-2025-17129: idm:DL1 security update (IMPORTANT)

16 дней назад
oracle-oval логотип
ELSA-2025-17085

ELSA-2025-17085: ipa security update (IMPORTANT)

15 дней назад
oracle-oval логотип
ELSA-2025-17084

ELSA-2025-17084: ipa security update (IMPORTANT)

16 дней назад

Уязвимостей на страницу