CVE-2013-2050: SQL Injection
It was found that the MiqPolicyController component of CloudForms Management Engine (CFME) was vulnerable to SQL injection. A remote attacker could use this flaw to execute arbitrary SQL statements in the CFME database.
Other sources
SQL injection vulnerability in the miqpolicy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2050?
CVE-2013-2050 is classified as a high-severity vulnerability due to its potential for remote exploitation and impact on the database.
How do I fix CVE-2013-2050?
To fix CVE-2013-2050, update the CloudForms Management Engine to the latest version recommended by Red Hat that addresses the SQL injection vulnerability.
What software versions are affected by CVE-2013-2050?
CVE-2013-2050 affects Red Hat CloudForms Management Engine version 5.1 and earlier versions of ManageIQ Enterprise Virtualization Manager up to 5.0.
What type of vulnerability is CVE-2013-2050?
CVE-2013-2050 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL statements in the database.
Can CVE-2013-2050 be exploited remotely?
Yes, CVE-2013-2050 can be exploited remotely, allowing attackers to gain unauthorized access to potentially sensitive data in the CFME database.