VYPR

Rhevm Reports

by Red Hat

CVEs (3)

  • CVE-2014-0201May 29, 2014
    risk 0.00cvss epss 0.00

    ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.

  • CVE-2014-0200May 29, 2014
    risk 0.00cvss epss 0.00

    The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permissions on the datasource configuration file (js-jboss7-ds.xml), which allows local users to obtain sensitive information by reading the file.

  • CVE-2014-0199May 29, 2014
    risk 0.00cvss epss 0.00

    The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.