4
CVSSv2

CVE-2014-0140

Published: 06/10/2014 Updated: 13/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Red Hat CloudForms 3.1 Management Engine (CFME) prior to 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms 3.0.5 management engine

redhat cloudforms 3.0.4 management engine 5.2.4

redhat cloudforms 3.0.3 management engine 5.2.3

redhat cloudforms 3.0.2 management engine 5.2.2

redhat cloudforms 3.0.1 management engine 5.2.1

redhat cloudforms 3.0 management engine 5.2

Vendor Advisories

It was found that Red Hat CloudForms exposed default routes that were reachable via HTTP(S) requests An authenticated user could use this flaw to access potentially sensitive controllers and actions that would allow for privilege escalation ...