CVE-2014-3486

The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
redhatcloudforms_3.0_management_engine
𝑥
≤ 5.2.4
redhatcloudforms_3.0_management_engine
5.2
redhatcloudforms_3.0_management_engine
5.2.1
redhatcloudforms_3.0_management_engine
5.2.1.6
redhatcloudforms_3.0_management_engine
5.2.2
redhatcloudforms_3.0_management_engine
5.2.3
redhatcloudforms_3.0_management_engine
5.2.3.2
𝑥
= Vulnerable software versions