REDHAT-BUG-959062: SQL Injection
It was found that the MiqPolicyController component of CloudForms Management Engine (CFME) was vulnerable to SQL injection. A remote attacker could use this flaw to execute arbitrary SQL statements in the CFME database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-959062?
The severity of REDHAT-BUG-959062 is critical due to the potential for remote SQL injection attacks.
How do I fix REDHAT-BUG-959062?
To fix REDHAT-BUG-959062, it is recommended to apply the latest security patches provided by Red Hat for the CloudForms Management Engine.
Who is impacted by the vulnerability REDHAT-BUG-959062?
The vulnerability REDHAT-BUG-959062 affects users of the CloudForms Management Engine, specifically versions prior to the fixed updates.
What kind of attacks can be executed through REDHAT-BUG-959062?
Through REDHAT-BUG-959062, attackers can execute arbitrary SQL statements, potentially compromising the CFME database.
Is there a workaround for REDHAT-BUG-959062?
Currently, there are no known workarounds for REDHAT-BUG-959062, so patching is the recommended approach.