CVE-2017-7497: Medium severity redhat CloudForms Management Engine vulnerability

Published May 11, 2017
·
Updated

Gellert Kis of Red Hat reports:

Dialog for creating cloud volumes (cinder provider) does not filter cloud tenants for user. In this way users can create storage volumes in any tenant. Not only in their own tenant. This currently affects CFME 5.7.2 and 5.8.0.

Other sources

The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.

Affected Software

2 affected components
redhat CloudForms Management Engine=5.7.2
redhat CloudForms Management Engine=5.8.0

Event History

May 11, 2017
Data Sourced
via Red Hat·04:37 PM
DescriptionSeverityAffected Software
Jul 27, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2017-7497?

CVE-2017-7497 is classified as a medium severity vulnerability due to its potential for unauthorized access to create storage volumes across tenants.

2

How do I fix CVE-2017-7497?

To fix CVE-2017-7497, upgrade the Red Hat CloudForms Management Engine to version 5.8.1 or later.

3

What versions of software are affected by CVE-2017-7497?

CVE-2017-7497 affects Red Hat CloudForms Management Engine versions 5.7.2 and 5.8.0.

4

What is the impact of CVE-2017-7497?

The impact of CVE-2017-7497 allows users to create storage volumes in any cloud tenant, leading to potential data exposure.

5

Who reported CVE-2017-7497?

CVE-2017-7497 was reported by Gellert Kis of Red Hat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203