PT-2014-3529 · Ovirt · Ovirt Engine Reports

Published

2014-05-29

·

Updated

2023-02-13

·

CVE-2014-0199

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ovirt-engine-reports versions prior to 3.3.3
Description The setup script stores the reports database password in cleartext, allowing local users to obtain sensitive information by reading an unspecified file.
Recommendations For versions prior to 3.3.3, update to version 3.3.3 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2014-0199
RHSA-2014:0558

Affected Products

Ovirt Engine Reports