CVE Vulnerabilities

CVE-2014-0202

Published: May 30, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.

Affected Software

Name Vendor Start Version End Version
Rhevm-dwh Redhat * 3.3.2 (including)
RHEV Manager version 3.3 RedHat ovirt_engine_dwh-root-0:3.3.3-1 *

References