VYPR

Cloudforms Management Engine

by Red Hat

CVEs (4)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-4457Hig0.497.50.00Jun 8, 2017CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
CVE-2013-20680.090.78Sep 28, 2013Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.
CVE-2013-20500.070.54Jan 11, 2014SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.
CVE-2013-41720.000.01Aug 23, 2013The Red Hat CloudForms Management Engine 5.1 allow remote administrators to execute arbitrary Ruby code via unspecified vectors.