SB2016050203 - Privilege escalation in Foreman



SB2016050203 - Privilege escalation in Foreman

Published: May 2, 2016

Security Bulletin ID SB2016050203
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2016-4451)

The vulnerability allows a remote authenticated attacker to bypass security restrictions.

The weakness exists due to improper enforcement of access controls on certain resources. A remote attacker can bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.


Remediation

Install update from vendor's website.