Описание
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
Ссылки
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:redhat:cloudforms_management_engine:2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.0016
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-384
Связанные уязвимости
redhat
около 12 лет назад
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
CVSS3: 7.5
github
больше 3 лет назад
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
EPSS
Процентиль: 37%
0.0016
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-384