VulnerabilityModified
CVE-2017-2614
This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
MEDIUM 6.3EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-640
- Affected
- redhat/enterprise virtualization
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2017-0257.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2614Issue Tracking, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0257.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2614Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.