CVE-2017-2664
26.07.2018, 14:29
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | cloudforms | 4.2 |
redhat | cloudforms | 4.6 |
redhat | cloudforms_management_engine | 𝑥 < 5.7.3 |
redhat | cloudforms_management_engine | 5.8 ≤ 𝑥 < 5.8.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References