CVE-2014-0199: Low severity redhat Rhevm-reports vulnerability
The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0199?
CVE-2014-0199 is classified as a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2014-0199?
To fix CVE-2014-0199, upgrade the ovirt-engine-reports package to version 3.3.3 or later.
What does CVE-2014-0199 affect?
CVE-2014-0199 affects the Red Hat Enterprise Virtualization reports package prior to version 3.3.3.
What kind of information is exposed in CVE-2014-0199?
CVE-2014-0199 exposes the reports database password in cleartext, allowing local users to access sensitive information.
Is CVE-2014-0199 a remote or local vulnerability?
CVE-2014-0199 is a local vulnerability since it requires local access to exploit.