First published: Thu Mar 23 2017(Updated: )
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cfme | <5.7.3 | 5.7.3 |
redhat/cfme | <5.8.1 | 5.8.1 |
Red Hat CloudForms | =4.2 | |
Red Hat CloudForms | =4.6 | |
Red Hat CloudForms Management Engine | <5.7.3 | |
Red Hat CloudForms Management Engine | >=5.8<5.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2664 is rated as a medium severity vulnerability due to insufficient RBAC controls.
To fix CVE-2017-2664, upgrade your version of CloudForms Management Engine to at least 5.8.1 or 5.7.3.
CVE-2017-2664 affects Red Hat CloudForms versions 4.2, 4.6, and certain versions of CloudForms Management Engine up to 5.7.3 and 5.8.x before 5.8.1.
The vendor for CVE-2017-2664 is Red Hat, responsible for the affected CloudForms products.
An attacker with access could use various methods within the CloudForms Rails application to escalate privileges due to the lack of RBAC controls in CVE-2017-2664.