First published: Fri May 03 2013(Updated: )
It was found that the MiqPolicyController component of CloudForms Management Engine (CFME) was vulnerable to SQL injection. A remote attacker could use this flaw to execute arbitrary SQL statements in the CFME database.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat CloudForms 3.0.4 Management Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-959062 is critical due to the potential for remote SQL injection attacks.
To fix REDHAT-BUG-959062, it is recommended to apply the latest security patches provided by Red Hat for the CloudForms Management Engine.
The vulnerability REDHAT-BUG-959062 affects users of the CloudForms Management Engine, specifically versions prior to the fixed updates.
Through REDHAT-BUG-959062, attackers can execute arbitrary SQL statements, potentially compromising the CFME database.
Currently, there are no known workarounds for REDHAT-BUG-959062, so patching is the recommended approach.