CVE-2014-0137
14.05.2014, 19:55
SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.
Vendor | Product | Version |
---|---|---|
redhat | cloudforms_3.0_management_engine | 𝑥 ≤ 5.2.3 |
redhat | cloudforms_3.0_management_engine | 5.2 |
redhat | cloudforms_3.0_management_engine | 5.2.1 |
redhat | cloudforms_3.0_management_engine | 5.2.2 |
𝑥
= Vulnerable software versions