CVE-2016-7062: High severity red hat storage console vulnerability
rhcon-ceph leaks password in plain text via command line parameter. Authenticated Local user can view passwords in plain text by ps -ef command.
https://bugzilla.redhat.com/showbug.cgi?id=1346379
Other sources
rhscon-ceph in Red Hat Storage Console 2 x8664 and Red Hat Storage Console Node 2 x8664 allows local users to obtain the password as cleartext.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7062?
CVE-2016-7062 is considered a moderate severity vulnerability due to the potential exposure of sensitive passwords.
How do I fix CVE-2016-7062?
To fix CVE-2016-7062, update to the latest version of Red Hat Storage Console and Red Hat Storage Console Node that addresses this issue.
Who is affected by CVE-2016-7062?
CVE-2016-7062 affects authenticated local users of Red Hat Storage Console version 2.0 and Red Hat Storage Console Node version 2.0.
What type of information is exposed in CVE-2016-7062?
CVE-2016-7062 exposes passwords in plain text through command line parameters, viewable by using the 'ps -ef' command.
Is CVE-2016-7062 easy to exploit?
CVE-2016-7062 requires local access, making it relatively easier to exploit for authenticated users on the affected systems.