6.5
CVE-2017-2664
- EPSS 0.22%
- Veröffentlicht 26.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:55
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Cloudforms Version4.2
Redhat ≫ Cloudforms Version4.6
Redhat ≫ Cloudforms Management Engine Version < 5.7.3
Redhat ≫ Cloudforms Management Engine Version >= 5.8 < 5.8.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.22% | 0.446 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
secalert@redhat.com | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.