High severity8.8NVD Advisory· Published Aug 19, 2016· Updated May 6, 2026
CVE-2016-4475
CVE-2016-4475
Description
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- projects.theforeman.org/issues/15268nvdPatchVendor Advisory
- projects.theforeman.org/projects/foreman/repository/revisions/a30ab44ed6f140f1791afc51a1e448afc2ff28f9nvdPatchVendor Advisory
- www.securityfocus.com/bid/92125nvdThird Party AdvisoryVDB Entry
- theforeman.org/security.htmlnvdVendor Advisory
- access.redhat.com/errata/RHBA-2016:1615nvd
News mentions
0No linked articles in our index yet.