Severity | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE ID | CVE-2017-2664 |
CVSSv3 |
8.5 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C] |
CWE ID | CWE-284 |
Exploitation vector | Network |
Public exploit | Not available |
Vulnerable software |
CloudForms |
Vulnerable software versions |
CloudForms 4.2 |
Vendor URL | Red Hat Inc. |
The vulnerability allows a remote authenticated attacker to gain elevated privileges on the targeted system.
The weakness exists due to insufficient role-based access control (RBAC) on certain methods within the rails application portion. A remote attacker can gain system privileges and conduct further attacks.
Install update from vendor's website.