Redhat

Enterprise Virtualization

35 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.46%
  • Published 25.02.2020 21:15:10
  • Last modified 21.11.2024 02:32:32

VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing...

  • EPSS 0.17%
  • Published 13.11.2019 17:15:13
  • Last modified 21.11.2024 02:18:41

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

Exploit
  • EPSS 0.13%
  • Published 04.11.2019 19:15:10
  • Last modified 21.11.2024 01:55:16

Insecure temporary file vulnerability in RedHat vsdm 4.9.6.

  • EPSS 0.04%
  • Published 27.07.2018 18:29:00
  • Last modified 21.11.2024 03:23:50

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with exp...

Exploit
  • EPSS 89.38%
  • Published 17.05.2018 16:29:00
  • Last modified 21.11.2024 03:59:12

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network ab...

  • EPSS 0.26%
  • Published 26.04.2018 17:29:00
  • Last modified 21.11.2024 03:59:07

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain acce...

  • EPSS 0.13%
  • Published 22.08.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.

Exploit
  • EPSS 0.06%
  • Published 20.04.2017 17:59:00
  • Last modified 20.04.2025 01:37:25

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which tr...

  • EPSS 0.05%
  • Published 14.12.2016 18:59:01
  • Last modified 12.04.2025 10:46:40

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.

  • EPSS 0.13%
  • Published 03.10.2016 18:59:07
  • Last modified 12.04.2025 10:46:40

The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.