CVE-2014-0176: XSS
Published Jul 7, 2014
·Updated
Cross-site scripting (XSS) vulnerability in application/panelcontrol in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
7 affected components
redhat Cloudforms 3.0 Management Engine<=5.2.4
redhat Cloudforms 3.0 Management Engine=5.2
redhat Cloudforms 3.0 Management Engine=5.2.1
redhat Cloudforms 3.0 Management Engine=5.2.1.6
redhat Cloudforms 3.0 Management Engine=5.2.2
redhat Cloudforms 3.0 Management Engine=5.2.3
redhat Cloudforms 3.0 Management Engine=5.2.3.2
Event History
Jul 7, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0176?
CVE-2014-0176 is classified as a medium-severity cross-site scripting vulnerability.
2
How do I fix CVE-2014-0176?
To fix CVE-2014-0176, update your CloudForms Management Engine to version 5.2.4.2 or later.
3
What versions of CloudForms are affected by CVE-2014-0176?
CVE-2014-0176 affects Red Hat CloudForms Management Engine versions prior to 5.2.4.2.
4
Can CVE-2014-0176 be exploited remotely?
Yes, remote attackers can exploit CVE-2014-0176 to inject arbitrary web scripts or HTML.
5
What type of vulnerability is CVE-2014-0176?
CVE-2014-0176 is a cross-site scripting (XSS) vulnerability.