CVE Vulnerabilities

CVE-2016-4471

Published: Jun 08, 2017 | Modified: Jun 15, 2017
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu

ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Cloudforms Redhat * 4.0 (including)
CloudForms Management Engine 5.6 RedHat cfme-0:5.6.0.13-1.el7cf *
CloudForms Management Engine 5.6 RedHat cfme-appliance-0:5.6.0.13-1.el7cf *
CloudForms Management Engine 5.6 RedHat cfme-gemset-0:5.6.0.13-1.el7cf *
CloudForms Management Engine 5.6 RedHat prince-0:9.0r2-10.el7cf *
CloudForms Management Engine 5.6 RedHat rh-postgresql94-postgresql-pglogical-0:1.0.1-3.el7cf *
CloudForms Management Engine 5.6 RedHat rh-postgresql94-postgresql-pglogical-output-0:1.0.1-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-bcrypt-0:3.1.10-3.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-escape_utils-0:1.1.0-2.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-eventmachine-0:1.0.7-6.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-ffi-0:1.9.8-4.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-hamlit-0:2.0.2-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-http_parser.rb-0:0.6.0-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-json-0:1.8.2-9.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-linux_block_device-0:0.1.0-2.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-memory_buffer-0:0.1.0-2.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-net_app_manageability-0:0.1.0-3.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-nio4r-0:1.2.1-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-nokogiri-0:1.6.6.2-3.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-pg-0:0.18.2-2.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-psych-0:2.0.13-4.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-puma-0:3.3.0-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-redhat_access_cfme-0:1.0.3-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-redhat_access_lib-0:0.0.6-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-rugged-0:0.23.3-1.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-thin-0:1.6.3-2.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-unf_ext-0:0.0.7.1-3.el7cf *
CloudForms Management Engine 5.6 RedHat rh-ruby22-rubygem-websocket-driver-0:0.6.3-1.el7cf *
CloudForms Management Engine 5.6 RedHat smem-0:1.4-1.el7cf *
CloudForms Management Engine 5.6 RedHat wmi-0:1.3.14-6.el7cf *

References