PT-2016-5960 · Red Hat · Red Hat Enterprise Virtualization Manager

·

CVE-2016-4443

·

Published

2016-12-14

·

Updated

2023-02-12

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Virtualization (RHEV) Manager version 3.6
Description The issue allows local users to access sensitive information, including encryption keys and certificates, by reading the engine-setup log file.
Recommendations For Red Hat Enterprise Virtualization (RHEV) Manager version 3.6, restrict access to the engine-setup log file to prevent unauthorized users from obtaining sensitive information.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4443
RHSA-2016:1929

Affected Products

Red Hat Enterprise Virtualization Manager