VulnerabilityModified
CVE-2013-4404
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.
MEDIUM 6.5EPSS 1.88%
Does this matter?
Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.
Description
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- redhat/enterprise mrg
- Source
- secalert@redhat.com
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=995038
- http://rhn.redhat.com/errata/RHSA-2013-1851.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1852.html
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=995038
- http://rhn.redhat.com/errata/RHSA-2013-1851.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1852.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.