6.5
CVSSv2

CVE-2016-4475

Published: 19/08/2016 Updated: 12/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The (1) Organization and (2) Locations APIs and UIs in Foreman prior to 1.11.4 and 1.12.x prior to 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman 1.12.0

theforeman foreman

Vendor Advisories

It was found that the foreman API and UI actions and URLs are not properly limited to the organizations and locations they were assigned to This could allow an attacker to view and update other organizations and locations in the system that they should not be allowed to ...