PT-2016-3798 · Postgresql+1 · Postgresql+1
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat CloudForms 3.2 Management Engine (CFME) version 5.4.4
Red Hat CloudForms 4.0 Management Engine (CFME) version 5.5.0
Description
The issue is related to improper encryption of data in the backend PostgreSQL database. This might allow local users to obtain sensitive data and gain privileges by accessing database exports or log files.
Recommendations
For Red Hat CloudForms 3.2 Management Engine (CFME) version 5.4.4, update to a version that properly encrypts data in the backend PostgreSQL database.
For Red Hat CloudForms 4.0 Management Engine (CFME) version 5.5.0, update to a version that properly encrypts data in the backend PostgreSQL database.
As a temporary workaround, consider restricting access to database exports and log files to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Postgresql
Red Hat Cloudforms