CVE-2018-1072
- EPSS 0.15%
- Veröffentlicht 26.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:07
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisio...
CVE-2015-7544
- EPSS 0.93%
- Veröffentlicht 25.09.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
CVE-2015-5293
- EPSS 0.28%
- Veröffentlicht 24.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
CVE-2015-0257
- EPSS 0.04%
- Veröffentlicht 01.05.2015 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading fi...
CVE-2015-0237
- EPSS 0.42%
- Veröffentlicht 01.05.2015 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by...
CVE-2014-3573
- EPSS 0.46%
- Veröffentlicht 18.10.2014 00:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or possibly have other unspecified impact via a craft...
CVE-2013-6434
- EPSS 0.29%
- Veröffentlicht 24.01.2014 18:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SP...
- EPSS 0.38%
- Veröffentlicht 03.07.2013 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service (disk space consumption) by cloning a VM from a snapshot.
CVE-2012-6115
- EPSS 0.06%
- Veröffentlicht 12.03.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to o...
- EPSS 0.57%
- Veröffentlicht 12.03.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption o...