CVE-2003-0084
Estado: ModificadaAlta (7.5)—
El paquete mod_auth_any en Red Hat Enterprise Linux 2.1 y otros sistemas operativos no escapa adecuadamente argumentos cuando llama a otros programas, lo que permite a atacantes ejecutar código arbitrarios mediante metacaractéres de shell.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.72%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://rhn.redhat.com/errata/RHSA-2003-114.html
- http://www.ciac.org/ciac/bulletins/n-090.shtml
- http://www.itlab.musc.edu/webNIS/mod_auth_any.html
- http://www.redhat.com/support/errata/RHSA-2003-113.html
- http://www.securityfocus.com/bid/7448
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11893
- http://rhn.redhat.com/errata/RHSA-2003-114.html
- http://www.ciac.org/ciac/bulletins/n-090.shtml
- http://www.itlab.musc.edu/webNIS/mod_auth_any.html
- http://www.redhat.com/support/errata/RHSA-2003-113.html
- http://www.securityfocus.com/bid/7448
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11893
JSON original (NVD)
Mostrar
{
"id": "CVE-2003-0084",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-05-12T04:00:00.000",
"references": [
{
"url": "http://rhn.redhat.com/errata/RHSA-2003-114.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ciac.org/ciac/bulletins/n-090.shtml",
"source": "cve@mitre.org"
},
{
"url": "http://www.itlab.musc.edu/webNIS/mod_auth_any.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2003-113.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/7448",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11893",
"source": "cve@mitre.org"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2003-114.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ciac.org/ciac/bulletins/n-090.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.itlab.musc.edu/webNIS/mod_auth_any.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2003-113.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/7448",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11893",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters."
},
{
"lang": "es",
"value": "El paquete mod_auth_any en Red Hat Enterprise Linux 2.1 y otros sistemas operativos no escapa adecuadamente argumentos cuando llama a otros programas, lo que permite a atacantes ejecutar código arbitrarios mediante metacaractéres de shell."
}
],
"lastModified": "2026-06-16T22:01:29.497",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mod_auth_any:mod_auth_any:1.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15E5FAE2-129D-4116-9938-0CEBC871C76E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}