VendorsRed Hatcloudforms_3.0_management_engine5.2.1.6
Vulnerabilities

Red Hat CloudForms 3.0 Management Engine 5.2.1.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2014-3486
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.
Published 2014-07-07 · Modified
6.9EPSS 0.004
CVE-2014-0180
The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via unspecified vectors.
Published 2014-07-07 · Modified
5.0EPSS 0.018
CVE-2014-0184
Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows local users to obtain sensitive information by reading the evm.log file.
Published 2014-07-07 · Modified
4.9EPSS 0.004
CVE-2014-3489
lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which makes it easier for remote attackers to guess passwords via a brute force attack.
Published 2014-07-07 · Modified
4.3EPSS 0.016
CVE-2014-0176
Cross-site scripting (XSS) vulnerability in application/panel_control in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2014-07-07 · Modified
4.3EPSS 0.014