PT-2018-4118 · Red Hat+1 · Red Hat Cloudforms Management Engine+1

Published

2018-01-11

·

Updated

2023-02-13

·

CVE-2014-0087

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ManageIQ (affected versions not specified) Red Hat CloudForms Management Engine (CFME) (affected versions not specified)
Description The issue allows remote authenticated users to bypass authorization and gain privileges. This is due to improper RBAC checking in the check privileges method, specifically related to the rbac user edit action.
Recommendations For ManageIQ, update the check privileges method in vmdb/app/controllers/application controller.rb to properly implement RBAC checking. For Red Hat CloudForms Management Engine (CFME), ensure that the check privileges method is updated to prevent unauthorized privilege escalation. As a temporary workaround, consider restricting access to the rbac user edit action until a proper fix is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2014-0087
RHSA-2015:0028

Affected Products

Manageiq
Red Hat Cloudforms Management Engine