Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-6115

Опубликовано: 17 дек. 2012
Источник: redhat
CVSS2: 4.7
EPSS Низкий

Описание

The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Virtualization 2ovirt-engine-configNot affected
RHEV Manager version 3.1org.ovirt.engine-rootFixedRHSA-2013:021104.02.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=905865rhev: rhevm-manage-domains logs admin passwords

EPSS

Процентиль: 20%
0.00064
Низкий

4.7 Medium

CVSS2

Связанные уязвимости

nvd
почти 13 лет назад

The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.

debian
почти 13 лет назад

The domain management tool (rhevm-manage-domains) in Red Hat Enterpris ...

github
больше 3 лет назад

The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.

EPSS

Процентиль: 20%
0.00064
Низкий

4.7 Medium

CVSS2