CVE-2013-4404: Medium severity red hat enterprise mrg vulnerability
Published Dec 23, 2013
·Updated
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.
Affected Software
1 affected component
redhat Enterprise MRG=2.4
Event History
Dec 23, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4404?
CVE-2013-4404 is rated as having a moderate severity level due to the potential for unauthorized access to sensitive information.
2
How do I fix CVE-2013-4404?
To fix CVE-2013-4404, upgrade to the patched versions provided by Red Hat for Enterprise MRG 2.4.
3
What software is affected by CVE-2013-4404?
CVE-2013-4404 affects Red Hat Enterprise MRG version 2.4.
4
What type of vulnerability is CVE-2013-4404?
CVE-2013-4404 is an access control vulnerability that allows users to bypass role restrictions.
5
Can CVE-2013-4404 allow remote access to sensitive data?
Yes, CVE-2013-4404 can allow remote authenticated users to access sensitive information due to improper role enforcement.