8.8
CVSSv3

CVE-2016-5402

Published: 31/10/2018 Updated: 12/02/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 802
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms 4.1

redhat cloudforms management engine 5.6

Vendor Advisories

Synopsis Important: CFME 563 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat CloudForms 41Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS ...
A code injection flaw was found in the way capacity and utilization imported control files are processed A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as ...