CVE-2016-5402: Code Injection
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-5402?
CVE-2016-5402 is a code injection flaw in the way capacity and utilization imported control files are processed.
What is the severity of CVE-2016-5402?
CVE-2016-5402 has a severity rating of 8.8, which is considered critical.
How does CVE-2016-5402 affect Redhat Cloudforms?
CVE-2016-5402 affects Redhat Cloudforms versions 4.1 and 5.6.
How can an attacker exploit CVE-2016-5402?
An authenticated attacker with access to the capacity and utilization feature can exploit CVE-2016-5402 to execute arbitrary code as the user CFME runs as.
Are there any references available for CVE-2016-5402?
Yes, you can find more information about CVE-2016-5402 at the following references: [1] http://rhn.redhat.com/errata/RHSA-2016-2839.html [2] http://www.securityfocus.com/bid/94612 [3] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-5402