Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7544

Опубликовано: 07 дек. 2015
Источник: redhat
CVSS2: 6.6
EPSS Низкий

Описание

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.

It was found that redhat-support-plugin-rhev passed a user-specified path and file name directly to the command line in the log viewer component. This could allow users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1269588redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV

EPSS

Процентиль: 76%
0.00926
Низкий

6.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.1
nvd
больше 8 лет назад

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.

CVSS3: 9.1
github
больше 3 лет назад

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.

EPSS

Процентиль: 76%
0.00926
Низкий

6.6 Medium

CVSS2