CVE-2012-2696

The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.7 UNKNOWN
ADJACENT_NETWORK
LOW
AV:A/AC:L/Au:S/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
redhatenterprise_virtualization_manager
𝑥
≤ 3.0
redhatenterprise_virtualization_manager
2.1
redhatenterprise_virtualization_manager
2.2
redhatenterprise_virtualization_manager
2.2.3
𝑥
= Vulnerable software versions
Common Weakness Enumeration