VendorsRed Hatcloudforms3.0
Vulnerabilities

Red Hat CloudForms 3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2014-0197
CFME: CSRF protection vulnerability via permissive check of the referrer header
Published 2019-12-13 · Modified
8.8EPSS 0.007
CVE-2014-0057
The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remote attackers to execute arbitrary methods via unspecified vectors.
Published 2014-03-18 · Modified
7.5EPSS 0.016
CVE-2013-6443
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
Published 2014-01-23 · Modified
6.8EPSS 0.006
CVE-2013-0186
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2019-11-01 · Modified
6.1EPSS 0.009
CVE-2013-4423
CloudForms stores user passwords in recoverable format
Published 2019-11-04 · Modified
5.5EPSS 0.003
CVE-2014-0081
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.
Published 2014-02-20 · Modified
4.3EPSS 0.040