CVE-2014-0184: Medium severity red hat cloudforms management engine vulnerability
Published Jul 7, 2014
·Updated
Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows local users to obtain sensitive information by reading the evm.log file.
Affected Software
7 affected components
redhat Cloudforms 3.0 Management Engine<=5.2.4
redhat Cloudforms 3.0 Management Engine=5.2
redhat Cloudforms 3.0 Management Engine=5.2.1
redhat Cloudforms 3.0 Management Engine=5.2.1.6
redhat Cloudforms 3.0 Management Engine=5.2.2
redhat Cloudforms 3.0 Management Engine=5.2.3
redhat Cloudforms 3.0 Management Engine=5.2.3.2
Event History
Jul 7, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0184?
CVE-2014-0184 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-0184?
To fix CVE-2014-0184, upgrade your Red Hat CloudForms Management Engine to version 5.2.4.2 or later.
3
Who is affected by CVE-2014-0184?
CVE-2014-0184 affects users of Red Hat CloudForms Management Engine versions prior to 5.2.4.2.
4
What type of information is exposed by CVE-2014-0184?
CVE-2014-0184 exposes the root password in the evm.log file, allowing local users to access sensitive information.
5
When was CVE-2014-0184 disclosed?
CVE-2014-0184 was disclosed and documented in 2014.