PT-2018-4118 · Red Hat+1 · Red Hat Cloudforms Management Engine+1

CVE-2014-0087

·

Publicado

2018-01-11

·

Atualizado

2023-02-13

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ManageIQ (affected versions not specified) Red Hat CloudForms Management Engine (CFME) (affected versions not specified)
Description The issue allows remote authenticated users to bypass authorization and gain privileges. This is due to improper RBAC checking in the check privileges method, specifically related to the rbac user edit action.
Recommendations For ManageIQ, update the check privileges method in vmdb/app/controllers/application controller.rb to properly implement RBAC checking. For Red Hat CloudForms Management Engine (CFME), ensure that the check privileges method is updated to prevent unauthorized privilege escalation. As a temporary workaround, consider restricting access to the rbac user edit action until a proper fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0087
RHSA-2015:0028

Produtos afetados

Manageiq
Red Hat Cloudforms Management Engine