PT-2018-4118 · Red Hat+1 · Red Hat Cloudforms Management Engine+1
CVE-2014-0087
·
Publicado
2018-01-11
·
Atualizado
2023-02-13
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ManageIQ (affected versions not specified)
Red Hat CloudForms Management Engine (CFME) (affected versions not specified)
Description
The issue allows remote authenticated users to bypass authorization and gain privileges. This is due to improper RBAC checking in the check privileges method, specifically related to the rbac user edit action.
Recommendations
For ManageIQ, update the check privileges method in vmdb/app/controllers/application controller.rb to properly implement RBAC checking.
For Red Hat CloudForms Management Engine (CFME), ensure that the check privileges method is updated to prevent unauthorized privilege escalation.
As a temporary workaround, consider restricting access to the rbac user edit action until a proper fix is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Manageiq
Red Hat Cloudforms Management Engine