Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-0087

Опубликовано: 11 янв. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*
Версия до 5.3 (исключая)

EPSS

Процентиль: 27%
0.00095
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

redhat
около 11 лет назад

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

CVSS3: 8.8
github
больше 3 лет назад

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

EPSS

Процентиль: 27%
0.00095
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-264