Insufficient Granularity of Access Control in FreeIPA - CVE-2025-7493
Published: October 1, 2025
Vulnerability details
The vulnerability allows a remote user to escalate privileges from host to domain administrator.
The vulnerability exists due the application does not validate the root@REALM canonical name, which can also be used as the realm administrator's name. A remote user can perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.
Affected software
Netezza Appliance
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3-kdcproxy
python3-jwcrypto
python3-custodia
custodia
ipa-healthcheck-core
ipa-healthcheck
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm
softhsm-devel
ipa (Red Hat package)
ipa-server-trust-ad
python2-ipaserver
python2-ipalib
python2-ipaclient
ipa-server-dns
ipa-server-common
ipa-client
ipa-python-compat
ipa-common
ipa-server
ipa-client-common
python3-ipatests
python3-ipaserver
python3-ipaclient
ipa-client-epn
ipa-client-samba
ipa-selinux
python3-ipalib
freeipa
python3-qrcode-core
python3-qrcode
bind-dyndb-ldap
How to mitigate CVE-2025-7493
Netezza Appliance - update to 1.0.1.0 fp278500
python3-kdcproxy - update to 0.4-5
python3-jwcrypto - update to 0.5.0-2
python3-custodia - update to 0.6.0-3
custodia - update to 0.6.0-3
ipa-healthcheck-core - update to 0.12-6
ipa-healthcheck - update to 0.12-6
slapi-nis - update to 0.60.0-4.0.1
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-2
softhsm - update to 2.6.0-5
softhsm-devel - update to 2.6.0-5
ipa (Red Hat package) - addressed in versions 4.6.8-5.el7_9.23, 4.9.8-11.el9_0.5, 4.10.1-12.el9_2.6, 4.11.0-15.el9_4.7, 4.12.2-14.el9_6.5, 4.12.2-15.el10_0.4
ipa-server-trust-ad - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
python2-ipaserver - update to 4.6.8-5.0.1
python2-ipalib - update to 4.6.8-5.0.1
python2-ipaclient - update to 4.6.8-5.0.1
ipa-server-dns - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-server-common - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-client - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-python-compat - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-common - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-server - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
ipa-client-common - addressed in versions 4.6.8-5.0.1, 4.9.13-20.0.1
python3-ipatests - update to 4.9.13-20.0.1
python3-ipaserver - update to 4.9.13-20.0.1
python3-ipaclient - update to 4.9.13-20.0.1
ipa-client-epn - update to 4.9.13-20.0.1
ipa-client-samba - update to 4.9.13-20.0.1
ipa-selinux - update to 4.9.13-20.0.1
python3-ipalib - update to 4.9.13-20.0.1
freeipa - addressed in versions 4.12.5-1.fc41, 4.12.5-1.fc42
python3-qrcode-core - update to 5.3-1
python3-qrcode - update to 5.3-1
bind-dyndb-ldap - update to 11.6-6
External References
Related Security Bulletins
- Privilege escalation in FreeIPA
- Fedora 42 update for freeipa
- Fedora 41 update for freeipa
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:client module
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for ipa
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 10 update for ipa
- Anolis OS update for idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:client module
- Anolis OS update for ipa
- Multiple vulnerabilities in IBM Netezza Appliance