Redhat

Enterprise Virtualization

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.46%
  • Veröffentlicht 25.02.2020 21:15:10
  • Zuletzt bearbeitet 21.11.2024 02:32:32

VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing...

  • EPSS 0.17%
  • Veröffentlicht 13.11.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 02:18:41

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

Exploit
  • EPSS 0.13%
  • Veröffentlicht 04.11.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 01:55:16

Insecure temporary file vulnerability in RedHat vsdm 4.9.6.

  • EPSS 0.04%
  • Veröffentlicht 27.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:50

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with exp...

Exploit
  • EPSS 89.38%
  • Veröffentlicht 17.05.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:12

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network ab...

  • EPSS 0.26%
  • Veröffentlicht 26.04.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:07

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain acce...

  • EPSS 0.13%
  • Veröffentlicht 22.08.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 20.04.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which tr...

  • EPSS 0.05%
  • Veröffentlicht 14.12.2016 18:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.

  • EPSS 0.13%
  • Veröffentlicht 03.10.2016 18:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.