CVE-2013-4172: Code Injection
Published Aug 23, 2013
·Updated
The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors.
Affected Software
1 affected component
redhat CloudForms Management Engine=5.1
Event History
Aug 23, 2013
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4172?
The severity of CVE-2013-4172 is classified as high due to the potential for remote code execution.
2
How do I fix CVE-2013-4172?
To fix CVE-2013-4172, update your Red Hat CloudForms Management Engine to the patched version provided in the security advisory.
3
What types of attacks can exploit CVE-2013-4172?
CVE-2013-4172 can be exploited by remote administrators to execute arbitrary Ruby code on the affected system.
4
Which versions of the Red Hat CloudForms Management Engine are affected by CVE-2013-4172?
Red Hat CloudForms Management Engine version 5.1 is affected by CVE-2013-4172.
5
Is user interaction required to exploit CVE-2013-4172?
No, CVE-2013-4172 can be exploited remotely without user interaction.