SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) prior to 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat cloudforms 3.0 management engine 5.2.1 |
||
redhat cloudforms 3.0 management engine |
||
redhat cloudforms 3.0 management engine 5.2.2 |
||
redhat cloudforms 3.0 management engine 5.2 |