PT-2018-4930 · Unknown+2 · Cfme+3

Adam Mariš

+1

·

Published

2018-10-31

·

Updated

2023-02-12

·

CVE-2016-5402

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions No specific software or version information is provided.
Description A code injection flaw was found in the way capacity and utilization imported control files are processed. This could allow a remote, authenticated attacker with access to the capacity and utilization feature to execute arbitrary code as the user CFME runs as.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2016-5402
RHSA-2016:2839

Affected Products

Cfme
Cloudforms
Cloudforms Management Engine
Manageiq