Cloudforms
Products
2- 6 CVEs
- 1 CVE
Recent CVEs
7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-7071 | Hig | 0.57 | 8.8 | 0.02 | Sep 10, 2018 | It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM. | ||
| CVE-2020-25716 | Hig | 0.53 | 8.1 | 0.01 | Jun 7, 2021 | A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for… | ||
| CVE-2019-14894 | Hig | 0.52 | 8.0 | 0.04 | Jun 22, 2020 | A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on… | ||
| CVE-2019-10177 | Med | 0.42 | 6.5 | 0.01 | Jun 27, 2019 | A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which… | ||
| CVE-2013-4423 | Med | 0.36 | 5.5 | 0.00 | Nov 4, 2019 | CloudForms stores user passwords in recoverable format | ||
| CVE-2017-15123 | Med | 0.35 | 5.3 | 0.01 | Jun 12, 2019 | A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created… | ||
| CVE-2016-3702 | Med | 0.35 | 5.3 | 0.01 | Apr 21, 2017 | Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information. |
- risk 0.57cvss 8.8epss 0.02
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.
- risk 0.53cvss 8.1epss 0.01
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for…
- risk 0.52cvss 8.0epss 0.04
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on…
- risk 0.42cvss 6.5epss 0.01
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which…
- risk 0.36cvss 5.5epss 0.00
CloudForms stores user passwords in recoverable format
- risk 0.35cvss 5.3epss 0.01
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created…
- risk 0.35cvss 5.3epss 0.01
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.