SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-2664

An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.

MEDIUM 6.5EPSS 1.32%

Does this matter?

Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.

Description

CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
1.32% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
redhat/cloudforms · redhat/cloudforms management engine
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.