https://seclists.org/oss-sec/2017/q1/470
Published Feb 22, 2017
·Updated
Affected Software
1 affected component
Foreman Foreman<1.15.0
Frequently Asked Questions
1
What is the severity of CVE-2016-7078?
CVE-2016-7078 is considered a medium-level vulnerability as it allows unauthorized access to resources.
2
How do I fix CVE-2016-7078?
To fix CVE-2016-7078, ensure that all user accounts are properly assigned to organizations or locations.
3
What systems are affected by CVE-2016-7078?
CVE-2016-7078 affects Foreman installations that have the organization or location features enabled.
4
Can CVE-2016-7078 be exploited remotely?
Yes, CVE-2016-7078 can be exploited remotely via the Foreman web UI or API.
5
Who is impacted by CVE-2016-7078?
Any user account in Foreman that is not linked to specific organizations or locations is impacted by CVE-2016-7078.