6.3
CVSSv3

CVE-2017-2614

Published: 27/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.3 | Impact Score: 3.7 | Exploitability Score: 2
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools prior to 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise virtualization 4.0

Vendor Advisories

Synopsis Important: ovirt-engine-extension-aaa-jdbc security update Type/Severity Security Advisory: Important Topic An update for ovirt-engine-extension-aaa-jdbc is now available for RHEV Engine version 40Red Hat Product Security has rated this update as having a security impact of Important A Common Vu ...
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools fail to correctly check for the current password if it is expired This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts ...