First published: Thu Sep 08 2016(Updated: )
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cfme | <5.8.1.2 | 5.8.1.2 |
redhat/cfme | <5.7.3.1 | 5.7.3.1 |
redhat/cfme | <5.6.3.0 | 5.6.3.0 |
Red Hat CloudForms | =4.2 | |
Red Hat CloudForms | =4.5 | |
Red Hat CloudForms Management Engine | >=5.6<5.6.3.0 | |
Red Hat CloudForms Management Engine | >=5.7<5.7.3.1 | |
Red Hat CloudForms Management Engine | >=5.8<5.8.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7047 is classified as a medium severity vulnerability.
To fix CVE-2016-7047, upgrade to CloudForms version 5.6.3.0, 5.7.3.1, or 5.8.1.2.
CVE-2016-7047 is an information disclosure vulnerability within the CloudForms API.
Users with permissions to the MiqReportResults capability in the CloudForms API prior to the patched versions are affected by CVE-2016-7047.
If exploited, CVE-2016-7047 could allow unauthorized users to view data from other tenants or groups.