CVE-2015-7502
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain…
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.
- CVSS 3.0
- 5.1 MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/cloudforms management engine · redhat/cloudforms
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-2620.htmlVendor Advisory
- https://access.redhat.com/errata/RHSA-2015:2551Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1283019Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2620.htmlVendor Advisory
- https://access.redhat.com/errata/RHSA-2015:2551Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1283019Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.