CVE Vulnerabilities

CVE-2016-7062

Published: Jun 27, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:L/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
4.8 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.

Affected Software

NameVendorStart VersionEnd Version
Storage_consoleRedhat2.0 (including)2.0 (including)
Storage_console_nodeRedhat2.0 (including)2.0 (including)
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7RedHatceph-ansible-0:1.0.5-34.el7scon*
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7RedHatceph-installer-0:1.0.15-2.el7scon*
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7RedHatrhscon-agent-0:0.0.19-1.el7scon*
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7RedHatrhscon-ceph-0:0.0.43-1.el7scon*
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7RedHatrhscon-core-0:0.0.45-1.el7scon*
Red Hat Storage Console 2 for Red Hat Enteprise Linux 7RedHatrhscon-ui-0:0.0.60-1.el7scon*

References