[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-2696Date: (C)2013-01-07   (M)2023-12-22


The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.7
Exploit Score: 5.1
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1027838
BID-56825
RHSA-2012:1506
enterprise-system-backend-sec-bypass(80545)

CPE    3
cpe:/a:redhat:enterprise_virtualization_manager:2.2
cpe:/a:redhat:enterprise_virtualization_manager:2.1
cpe:/a:redhat:enterprise_virtualization_manager:2.2.3
CWE    1
CWE-264

© SecPod Technologies