CVE Vulnerabilities

CVE-2014-0087

Published: Jan 11, 2018 | Modified: Feb 13, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

Affected Software

Name Vendor Start Version End Version
Cloudforms_management_engine Redhat * 5.3 (excluding)
CloudForms Management Engine 5.3 RedHat cfme-0:5.3.2.6-1.el6cf *
CloudForms Management Engine 5.3 RedHat ruby193-rubygem-fog-0:1.19.0-2.el6cf *
CloudForms Management Engine 5.3 RedHat ruby193-rubygem-linux_admin-0:0.9.4-1.el6cf *

References