CVE-2016-4455

The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_hpc_node
6.0
redhatenterprise_linux_hpc_node
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
redhatsubscription-manager
𝑥
≤ 1.17.6-1
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
python-rhsm
RHEL 6
0:1.18.6-1.el6
fixed
RHEL 7
0:1.17.9-1.el7
fixed
python-rhsm-certificates
RHEL 6
0:1.18.6-1.el6
fixed
RHEL 7
0:1.17.9-1.el7
fixed
subscription-manager
RHEL 6
0:1.18.10-1.el6
fixed
RHEL 7
0:1.17.15-1.el7
fixed
subscription-manager-firstboot
RHEL 6
0:1.18.10-1.el6
fixed
subscription-manager-gui
RHEL 6
0:1.18.10-1.el6
fixed
RHEL 7
0:1.17.15-1.el7
fixed
subscription-manager-initial-setup-addon
RHEL 7
0:1.17.15-1.el7
fixed
subscription-manager-migration
RHEL 6
0:1.18.10-1.el6
fixed
RHEL 7
0:1.17.15-1.el7
fixed
subscription-manager-migration-data
RHEL 6
0:2.0.34-1.el6
fixed
RHEL 7
0:2.0.31-1.el7
fixed
subscription-manager-plugin-container
RHEL 6
0:1.18.10-1.el6
fixed
RHEL 7
0:1.17.15-1.el7
fixed
subscription-manager-plugin-ostree
RHEL 7
0:1.17.15-1.el7
fixed
Common Weakness Enumeration