CVE-2012-2696
published 2013-01-04CVE-2012-2696: The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to…
PriorityP417low2.7CVSS 2.0
AVAACLAuSCPINAN
EPSS
0.78%
51.8th percentile
The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | <= 3.0 | — |
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
CVSS provenance
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rhev: backend allows unprivileged queries
vendor_redhat·2012-12-04·CVSS 2.7
CVE-2012-2696 [LOW] rhev: backend allows unprivileged queries
rhev: backend allows unprivileged queries
The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.
Statement: This issue does affect Red Hat Enterprise Virtualization 2 and 3.
Red Hat Enterprise Virtualization 2 is now in Production 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Virtualization Life Cycle: https://access.redhat.com/support/policy/updates/rhev/.
Package: ovirt-engine-backend (Red Hat Enterprise Virtualization 2) - Will not fix
GHSA
GHSA-4pfr-fjxw-j2c5: The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3
ghsa_unreviewed·2022-05-17
CVE-2012-2696 [LOW] GHSA-4pfr-fjxw-j2c5: The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3
The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1506.htmlhttp://www.securityfocus.com/bid/56825http://www.securitytracker.com/id?1027838https://exchange.xforce.ibmcloud.com/vulnerabilities/80545http://rhn.redhat.com/errata/RHSA-2012-1506.htmlhttp://www.securityfocus.com/bid/56825http://www.securitytracker.com/id?1027838https://exchange.xforce.ibmcloud.com/vulnerabilities/80545
2013-01-04
Published