6.5
CVSSv2

CVE-2014-3642

Published: 06/10/2014 Updated: 13/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) prior to 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms 3.0.5 management engine

redhat cloudforms 3.0.4 management engine 5.2.4

redhat cloudforms 3.0.3 management engine 5.2.3

redhat cloudforms 3.0.2 management engine 5.2.2

redhat cloudforms 3.0.1 management engine 5.2.1

redhat cloudforms 3.0 management engine 5.2

Vendor Advisories

It was found that Red Hat CloudForms contained an insecure send method that accepted user-supplied arguments An authenticated user could use this flaw to modify the program flow in a way that could result in privilege escalation ...