PT-2014-2542 · Manageiq+1 · Manageiq Enterprise Virtualization Manager+1

CVE-2013-2050

·

Publicado

2014-01-11

·

Atualizado

2023-02-13

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat CloudForms 2.0 Management Engine (CFME) versions 5.1 and earlier ManageIQ Enterprise Virtualization Manager versions 5.0 and earlier
Description The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved via the profile[] parameter in an explorer action in the miq policy controller.
Recommendations For Red Hat CloudForms 2.0 Management Engine (CFME) versions 5.1 and earlier, avoid using the profile[] parameter in explorer actions until a fix is available. For ManageIQ Enterprise Virtualization Manager versions 5.0 and earlier, restrict access to the miq policy controller to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2050

Produtos afetados

Manageiq Enterprise Virtualization Manager
Red Hat Cloudforms