CVE Vulnerabilities

CVE-2012-6115

Published: Mar 12, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.7 MODERATE
AV:L/AC:M/Au:N/C:C/I:N/A:N
RedHat/V3
Ubuntu

The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.

Affected Software

Name Vendor Start Version End Version
Enterprise_virtualization_manager Redhat * 3.1 (including)
Enterprise_virtualization_manager Redhat 2.1 (including) 2.1 (including)
Enterprise_virtualization_manager Redhat 2.2 (including) 2.2 (including)
Enterprise_virtualization_manager Redhat 2.2.3 (including) 2.2.3 (including)
Enterprise_virtualization_manager Redhat 3.0 (including) 3.0 (including)
RHEV Manager version 3.1 RedHat org.ovirt.engine-root-0:3.1.0-43 *

References