First published: Fri Jul 27 2018(Updated: )
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Enterprise Virtualization | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2614 is a vulnerability that allows an attacker to change the password on accounts with expired passwords in the rhvm database.
The severity of CVE-2017-2614 is medium with a CVSS score of 6.3.
Redhat Enterprise Virtualization 4.0 is affected by CVE-2017-2614.
An attacker with access can exploit CVE-2017-2614 by changing the password on accounts with expired passwords.
Yes, you can find more information about CVE-2017-2614 at the following links: [Redhat Errata RHSA-2017-0257](http://rhn.redhat.com/errata/RHSA-2017-0257.html) and [Bugzilla - CVE-2017-2614](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2614).