CVE Vulnerabilities

CVE-2015-0237

Published: May 01, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
4.3 MODERATE
AV:A/AC:H/Au:S/C:N/I:N/A:C
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_virtualization_managerRedhat*3.5.0 (including)
RHEV Manager version 3.5RedHatorg.ovirt.engine-root-0:3.5.1-4*

References