VYPR
Medium severity4.1NVD Advisory· Published Jul 27, 2018· Updated Jun 17, 2026

CVE-2017-7497

CVE-2017-7497

Description

The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:redhat:cloudforms_management_engine:5.7.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:cloudforms_management_engine:5.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:cloudforms_management_engine:5.8.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.