Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4443

Опубликовано: 02 сент. 2016
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.

A flaw was found in RHEV Manager, where it wrote sensitive data to the engine-setup log file. A local attacker could exploit this flaw to view sensitive information such as encryption keys and certificates (which could then be used to steal other sensitive information such as passwords).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Gluster Storage 3.1org.ovirt.engine-rootWill not fix
RHEV Manager version 3.6org.ovirt.engine-rootFixedRHSA-2016:192921.09.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1335106org.ovirt.engine-root: engine-setup logs contained information for extracting admin password

EPSS

Процентиль: 15%
0.00047
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
nvd
около 9 лет назад

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.

CVSS3: 5.5
github
больше 3 лет назад

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.

EPSS

Процентиль: 15%
0.00047
Низкий

4.9 Medium

CVSS2