Red Hat CloudForms Management Engine CVE-2017-2664 Privilege Escalation Vulnerability
BID:100148
CVE-2017-2664 |Info
Red Hat CloudForms Management Engine CVE-2017-2664 Privilege Escalation Vulnerability
| Bugtraq ID: | 100148 |
| Class: | Design Error |
| CVE: |
CVE-2017-2664 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2017 12:00AM |
| Updated: | Aug 02 2017 12:00AM |
| Credit: | Libor Pichler and Martin Povolny from Red Hat. |
| Vulnerable: |
Redhat CloudForms Management Engine 5.8 |
| Not Vulnerable: | |
Discussion
Red Hat CloudForms Management Engine CVE-2017-2664 Privilege Escalation Vulnerability
Red Hat CloudForms Management Engine is prone to a privilege-escalation vulnerability.
An attacker can leverage this issue to gain elevated privileges. This may aid in further attacks.
Red Hat CloudForms Management Engine 5.8 is vulnerable.
Red Hat CloudForms Management Engine is prone to a privilege-escalation vulnerability.
An attacker can leverage this issue to gain elevated privileges. This may aid in further attacks.
Red Hat CloudForms Management Engine 5.8 is vulnerable.
Exploit / POC
Red Hat CloudForms Management Engine CVE-2017-2664 Privilege Escalation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at:maitto:[email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at:maitto:[email protected].
Solution / Fix
Red Hat CloudForms Management Engine CVE-2017-2664 Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat CloudForms Management Engine CVE-2017-2664 Privilege Escalation Vulnerability
References:
References:
- Bug 1435393 - (CVE-2017-2664) CVE-2017-2664 CloudForms: lack of RBAC on various (Red Hat)
- CVE-2017-2664 (Red Hat)
- Red Hat CloudForms Management Engine Homepage (Red Hat)
- RHSA-2017:1758 - Security Advisory (Red Hat)