CVE-2014-0200: Low severity redhat Rhevm-reports vulnerability
The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permissions on the datasource configuration file (js-jboss7-ds.xml), which allows local users to obtain sensitive information by reading the file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0200?
CVE-2014-0200 is considered a moderate severity vulnerability due to the exposure of sensitive information to local users.
How do I fix CVE-2014-0200?
To fix CVE-2014-0200, update the rhevm-reports package to version 3.3.3-1 or later.
What types of systems are affected by CVE-2014-0200?
CVE-2014-0200 affects Red Hat Enterprise Virtualization Manager reports versions prior to 3.3.3.
What files are involved in CVE-2014-0200?
CVE-2014-0200 involves world-readable permissions on the datasource configuration file js-jboss7-ds.xml.
Can local user access be restricted to mitigate CVE-2014-0200?
Yes, restricting access to the js-jboss7-ds.xml file can help mitigate the risks associated with CVE-2014-0200.