6.5
CVSSv2

CVE-2014-0137

Published: 14/05/2014 Updated: 13/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) prior to 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms 3.0 management engine 5.2.1

redhat cloudforms 3.0 management engine

redhat cloudforms 3.0 management engine 5.2.2

redhat cloudforms 3.0 management engine 5.2

Vendor Advisories

SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5232 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResultexists ...