Red Hat CloudForms Management Engine 'saved_report_delete' Action SQL Injection Vulnerability
BID:67513
Info
Red Hat CloudForms Management Engine 'saved_report_delete' Action SQL Injection Vulnerability
| Bugtraq ID: | 67513 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0137 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2014 12:00AM |
| Updated: | May 15 2014 12:00AM |
| Credit: | Jan Rusnacko |
| Vulnerable: |
Redhat CloudForms Management Engine 5.2.3 Redhat CloudForms Management Engine 5.2.2 Redhat CloudForms Management Engine 5.2.1 6 Redhat CloudForms Management Engine 5.2.1 Redhat CloudForms Management Engine 5.2.1 Redhat CloudForms Management Engine 5.1 |
| Not Vulnerable: |
Redhat CloudForms Management Engine 5.2.3.2 |
Discussion
Red Hat CloudForms Management Engine 'saved_report_delete' Action SQL Injection Vulnerability
Red Hat CloudForms Management Engine is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Red Hat CloudForms Management Engine (CFME) prior to 5.2.3.2 are vulnerable.
Red Hat CloudForms Management Engine is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Red Hat CloudForms Management Engine (CFME) prior to 5.2.3.2 are vulnerable.
Exploit / POC
Red Hat CloudForms Management Engine 'saved_report_delete' Action SQL Injection Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
Red Hat CloudForms Management Engine 'saved_report_delete' Action SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat CloudForms Management Engine 'saved_report_delete' Action SQL Injection Vulnerability
References:
References: