Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5402

Опубликовано: 30 нояб. 2016
Источник: redhat
CVSS3: 8.8
CVSS2: 8.5

Описание

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5.5cfmeWill not fix
CloudForms Management Engine 5.6cfmeFixedRHSA-2016:283930.11.2016
CloudForms Management Engine 5.6cfme-applianceFixedRHSA-2016:283930.11.2016
CloudForms Management Engine 5.6cfme-gemsetFixedRHSA-2016:283930.11.2016
CloudForms Management Engine 5.6freeipmiFixedRHSA-2016:283930.11.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1357559cfme: RCE via Capacity & Utilization feature

8.8 High

CVSS3

8.5 High

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
больше 7 лет назад

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

CVSS3: 8.8
github
больше 3 лет назад

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

8.8 High

CVSS3

8.5 High

CVSS2