CVE Vulnerabilities

CVE-2016-7062

Published: Jun 27, 2017 | Modified: Jul 05, 2017
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:L/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
4.8 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Ubuntu

rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.

Affected Software

Name Vendor Start Version End Version
Storage_console Redhat 2.0 (including) 2.0 (including)
Storage_console_node Redhat 2.0 (including) 2.0 (including)
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7 RedHat ceph-ansible-0:1.0.5-34.el7scon *
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7 RedHat ceph-installer-0:1.0.15-2.el7scon *
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7 RedHat rhscon-agent-0:0.0.19-1.el7scon *
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7 RedHat rhscon-ceph-0:0.0.43-1.el7scon *
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7 RedHat rhscon-core-0:0.0.45-1.el7scon *
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7 RedHat rhscon-ui-0:0.0.60-1.el7scon *

References