CVE-2016-3702: Infoleak
Internally CFME uses AES-256-CBC encryption to encrypt important data before it is saved in the database. This encryption mode is vulnerable to padding oracle attack and CFME does allow attacker to submit forged ciphertexts for encryption and observe the result.
Other sources
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3702?
CVE-2016-3702 is classified as a medium severity vulnerability due to the potential for padding oracle attacks.
How do I fix CVE-2016-3702?
To mitigate CVE-2016-3702, it is recommended to upgrade to a patched version of Red Hat CloudForms Management Engine beyond 5.0.
What systems are affected by CVE-2016-3702?
CVE-2016-3702 affects Red Hat CloudForms Management Engine version 5.0 specifically.
Can CVE-2016-3702 lead to data exposure?
Yes, if exploited, CVE-2016-3702 can allow attackers to decrypt sensitive information, leading to potential data exposure.
Was CVE-2016-3702 publicly disclosed?
Yes, CVE-2016-3702 has been publicly disclosed and details regarding its impact and mitigation are available.