CVE-2017-2664: Medium severity red hat cloudforms vulnerability
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.
Other sources
Libor Pichler and Martin Povolny report:
Cloudforms lacks RBAC controls on a variety of methods potentially allowing authenticated users to escalate privileges and use methods they should not have access to.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2664?
CVE-2017-2664 is rated as a medium severity vulnerability due to insufficient RBAC controls.
How do I fix CVE-2017-2664?
To fix CVE-2017-2664, upgrade your version of CloudForms Management Engine to at least 5.8.1 or 5.7.3.
What products are affected by CVE-2017-2664?
CVE-2017-2664 affects Red Hat CloudForms versions 4.2, 4.6, and certain versions of CloudForms Management Engine up to 5.7.3 and 5.8.x before 5.8.1.
Who is the vendor for CVE-2017-2664?
The vendor for CVE-2017-2664 is Red Hat, responsible for the affected CloudForms products.
What types of attacks are possible with CVE-2017-2664?
An attacker with access could use various methods within the CloudForms Rails application to escalate privileges due to the lack of RBAC controls in CVE-2017-2664.