CVE-2016-6813
- EPSS 5.59%
- Veröffentlicht 06.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 02:56:52
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to re...
CVE-2013-4317
- EPSS 1.17%
- Veröffentlicht 06.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 01:55:20
In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
CVE-2016-3085
- EPSS 2.86%
- Veröffentlicht 10.06.2016 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vector...
CVE-2015-3252
- EPSS 2.17%
- Veröffentlicht 08.02.2016 19:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
CVE-2015-3251
- EPSS 2.45%
- Veröffentlicht 08.02.2016 19:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
- EPSS 3.18%
- Veröffentlicht 15.01.2015 15:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
- EPSS 2.56%
- Veröffentlicht 10.12.2014 15:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
- EPSS 6.47%
- Veröffentlicht 23.05.2014 14:55:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force ...
- EPSS 5.82%
- Veröffentlicht 23.05.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.
- EPSS 2.15%
- Veröffentlicht 15.01.2014 16:08:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.