4
CVSSv2

CVE-2017-2664

Published: 26/07/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

CloudForms Management Engine (cfme) prior to 5.7.3 and 5.8.x prior to 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms management engine

redhat cloudforms 4.6

redhat cloudforms 4.2

Vendor Advisories

Synopsis Important: Red Hat CloudForms security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for cfme, cfme-appliance, and cfme-gemset is now available for CloudForms Management Engine 57Red Hat Product Security has rated this update as having a security impa ...