Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
redhat cloudforms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2012-3538
Pulp in Red Hat CloudForms prior to 1.1 logs administrative passwords in a world-readable file, which allows local users to read pulp administrative passwords by reading production.log.
Redhat Cloudforms
NA
CVE-2012-5605
Grinder in Red Hat CloudForms prior to 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.
Redhat Cloudforms
NA
CVE-2012-4574
Pulp in Red Hat CloudForms prior to 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.
Redhat Cloudforms
9.1
CVSSv3
CVE-2020-14325
Red Hat CloudForms prior to 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious malicious user to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator,...
Redhat Cloudforms
8.1
CVSSv3
CVE-2020-25716
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-1...
Redhat Cloudforms
NA
CVE-2012-5604
The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote malicious users to bypass authentication via unspecified vectors.
Redhat Cloudforms 1.1
5.5
CVSSv3
CVE-2013-4423
CloudForms stores user passwords in recoverable format
Redhat Cloudforms 3.0
4.3
CVSSv3
CVE-2019-10159
cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.
Redhat Cfme-gemset
Redhat Cloudforms 4.7
7.2
CVSSv3
CVE-2017-12148
A flaw was found in Ansible Tower's interface prior to 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository...
Redhat Ansible Tower
Redhat Cloudforms 4.5
9.1
CVSSv3
CVE-2020-14324
A high severity vulnerability was found in all active versions of Red Hat CloudForms prior to 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This fla...
Redhat Cloudforms Management Engine
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »