9.1
CVSSv3

CVE-2020-14325

Published: 11/08/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Red Hat CloudForms prior to 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious malicious user to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms

Vendor Advisories

Synopsis Critical: CloudForms 4716 security, bug fix and enhancement update Type/Severity Security Advisory: Critical Topic An update is now available for CloudForms Management Engine 510Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scorin ...
Synopsis Critical: CloudForms 507 bug fix and enhancement update Type/Severity Security Advisory: Critical Topic An update is now available for CloudForms Management Engine 511Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (C ...