VulnerabilityModified
CVE-2016-4443
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
MEDIUM 5.5EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- redhat/enterprise virtualization
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-1929.htmlMitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92751Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036863Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1335106Issue Tracking, VDB Entry, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1929.htmlMitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/92751Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036863Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1335106Issue Tracking, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.