First published: Tue Aug 30 2016(Updated: )
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization | =4.0 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5432 is rated as a medium severity vulnerability.
To fix CVE-2016-5432, it is recommended to upgrade to a patched version of Red Hat Enterprise Virtualization above 4.0.
CVE-2016-5432 allows local users to obtain sensitive database provisioning information by reading log files.
CVE-2016-5432 affects Red Hat Enterprise Virtualization version 4.0.
Mitigation for CVE-2016-5432 includes restricting access to log files and ensuring that only authorized users can operate ovirt-engine-provisiondb.