PT-2019-5697 · Red Hat · Cloudforms Management Engine

Published

2019-11-06

·

Updated

2023-02-12

·

CVE-2019-14894

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CloudForms Management Engine versions 5.10 through 5.11
Description The issue is related to insufficient input validation, allowing a remote attacker to elevate privileges to root level and execute arbitrary code. An attacker logged into the management console can exploit this flaw to execute arbitrary shell commands on the CloudForms server as root through NFS schedule backup.
Recommendations For versions 5.10 and 5.11, consider restricting access to the management console and NFS schedule backup feature until a patch is available. As a temporary workaround, limit the execution of arbitrary shell commands on the CloudForms server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-05828
CVE-2019-14894
RHSA-2020:0588
RHSA-2020:0589

Affected Products

Cloudforms Management Engine