CVE-2016-5432: Low severity red hat enterprise virtualization vulnerability
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
Other sources
When ovirt-engine-provisiondb, a utility usually called by engine-backup, was passed one of the '--provisiondb' options to create postgresql DBs/users, the password of the created user is stored in the log file in plain text.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5432?
CVE-2016-5432 is rated as a medium severity vulnerability.
How do I fix CVE-2016-5432?
To fix CVE-2016-5432, it is recommended to upgrade to a patched version of Red Hat Enterprise Virtualization above 4.0.
What type of information is exposed due to CVE-2016-5432?
CVE-2016-5432 allows local users to obtain sensitive database provisioning information by reading log files.
Which software is affected by CVE-2016-5432?
CVE-2016-5432 affects Red Hat Enterprise Virtualization version 4.0.
Are there any mitigation strategies for CVE-2016-5432?
Mitigation for CVE-2016-5432 includes restricting access to log files and ensuring that only authorized users can operate ovirt-engine-provisiondb.