CVE-2017-2614: Input Validation
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2614?
CVE-2017-2614 is a vulnerability that allows an attacker to change the password on accounts with expired passwords in the rhvm database.
What is the severity of CVE-2017-2614?
The severity of CVE-2017-2614 is medium with a CVSS score of 6.3.
What software is affected by CVE-2017-2614?
Redhat Enterprise Virtualization 4.0 is affected by CVE-2017-2614.
How can an attacker exploit CVE-2017-2614?
An attacker with access can exploit CVE-2017-2614 by changing the password on accounts with expired passwords.
Are there any references for CVE-2017-2614?
Yes, you can find more information about CVE-2017-2614 at the following links: [Redhat Errata RHSA-2017-0257](http://rhn.redhat.com/errata/RHSA-2017-0257.html) and [Bugzilla - CVE-2017-2614](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2614).