{"api_version":"1","generated_at":"2026-07-23T14:20:24+00:00","cve":"CVE-2014-3561","urls":{"html":"https://cve.report/CVE-2014-3561","api":"https://cve.report/api/cve/CVE-2014-3561.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-3561","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-3561"},"summary":{"title":"CVE-2014-3561","description":"The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.","state":"PUBLISHED","assigner":"redhat","published_at":"2014-12-05 16:59:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2014-1947.html","name":"http://rhn.redhat.com/errata/RHSA-2014-1947.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1031291","name":"http://www.securitytracker.com/id/1031291","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Enterprise Virtualization Manager Log Collector Lets Local Users View the Database Password - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99096","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99096","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2014:1947","name":"MISC:https://access.redhat.com/errata/RHSA-2014:1947","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2014-3561","name":"MISC:https://access.redhat.com/security/cve/CVE-2014-3561","refsource":"MITRE","tags":[],"title":"CVE-2014-3561 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1122781","name":"MISC:https://bugzilla.redhat.com/show_bug.cgi?id=1122781","refsource":"MITRE","tags":[],"title":"1122781 – (CVE-2014-3561) CVE-2014-3561 ovirt-engine-log-collector: database password disclosed in process listing","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-3561","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3561","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"3561","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"enterprise_virtualization","cpe6":"3.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:50:17.352Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"rhevm-log-collector-info-disc(99096)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99096"},{"name":"1031291","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031291"},{"name":"RHSA-2014:1947","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1947.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-12-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"rhevm-log-collector-info-disc(99096)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99096"},{"name":"1031291","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031291"},{"name":"RHSA-2014:1947","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1947.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2014-3561","datePublished":"2014-12-05T16:00:00.000Z","dateReserved":"2014-05-14T00:00:00.000Z","dateUpdated":"2024-08-06T10:50:17.352Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-12-05 16:59:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:enterprise_virtualization:3.4:*:*:*:*:*:*:*","matchCriteriaId":"FDA49BAA-D188-4F05-9AE8-E5A736EE1267"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"3561","Ordinal":"1","Title":"CVE-2014-3561","CVE":"CVE-2014-3561","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"3561","Ordinal":"1","NoteData":"The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.","Type":"Description","Title":"CVE-2014-3561"},{"CveYear":"2014","CveId":"3561","Ordinal":"2","NoteData":"2014-12-05","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"3561","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}