CVE-2012-4064: Medium severity eucalyptus vulnerability
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gain privileges by sending a message to (1) Cloud Controller or (2) Walrus with the internal message format and a modified user id.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4064?
CVE-2012-4064 has a medium severity rating due to potential privilege escalation risks.
How do I fix CVE-2012-4064?
To mitigate CVE-2012-4064, upgrade Eucalyptus to version 3.1.1 or later.
What products are affected by CVE-2012-4064?
CVE-2012-4064 affects Eucalyptus versions up to 3.1.0, along with several 1.x and 2.x versions.
Who is affected by CVE-2012-4064?
Remote authenticated users can be potentially affected by CVE-2012-4064 through unauthorized privilege escalation.
What does CVE-2012-4064 vulnerability involve?
CVE-2012-4064 involves improper restrictions on external SOAP web-services messages, leading to privilege escalation.