3.3
CVSSv3

CVE-2016-4455

Published: 14/04/2017 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Subscription Manager package (aka subscription-manager) prior to 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux hpc node 6.0

redhat enterprise linux hpc node 7.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat subscription-manager

Vendor Advisories

Synopsis Moderate: subscription-manager security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for subscription-manager, subscription-manager-migration-data, and python-rhsm is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this u ...
Synopsis Moderate: subscription-manager security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for subscription-manager, subscription-manager-migration-data, and python-rhsm is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this u ...
It was found that subscription-manager set weak permissions on files in /var/lib/rhsm/, causing an information disclosure A local, unprivileged user could use this flaw to access sensitive data that could potentially be used in a social engineering attack ...