CVE-2012-5616
published 2013-01-22CVE-2012-5616: Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file…
PriorityP49low1.5CVSS 2.0
AVLACMAuSCPINAN
EPSS
0.57%
43.1th percentile
Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cloudstack | — | — |
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | cloudplatform | <= 3.0.5 | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | xenserver | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2012-5616: Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf l
vendor_citrix·2013-01-22·CVSS 1.5
CVE-2012-5616 [LOW] CWE-255 CVE-2012-5616: Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf l
CVE-2012-5616: Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
Citrix
Citrix Security Bulletin CTX136163
vendor_citrix·CVSS 1.5
CVE-2012-5616 [LOW] Citrix Security Bulletin CTX136163
Citrix Security Bulletin CTX136163
CVE References: CVE-2012-5616, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
GHSA
GHSA-3pqh-mpvw-5fr2: Apache CloudStack 4
ghsa_unreviewed·2022-05-17
CVE-2012-5616 [LOW] GHSA-3pqh-mpvw-5fr2: Apache CloudStack 4
Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mail-archives.apache.org/mod_mbox/incubator-cloudstack-users/201301.mbox/%3C1BD2169F-BBFE-4E27-B50F-F17D7D08B565%40stratosec.co%3Ehttp://osvdb.org/89070http://osvdb.org/89146http://osvdb.org/89147http://seclists.org/fulldisclosure/2013/Jan/65http://secunia.com/advisories/51366http://secunia.com/advisories/51821http://secunia.com/advisories/51827http://support.citrix.com/article/CTX136163http://www.securityfocus.com/bid/57225http://www.securityfocus.com/bid/57259http://www.securitytracker.com/id?1027978http://mail-archives.apache.org/mod_mbox/incubator-cloudstack-users/201301.mbox/%3C1BD2169F-BBFE-4E27-B50F-F17D7D08B565%40stratosec.co%3Ehttp://osvdb.org/89070http://osvdb.org/89146http://osvdb.org/89147http://seclists.org/fulldisclosure/2013/Jan/65http://secunia.com/advisories/51366http://secunia.com/advisories/51821http://secunia.com/advisories/51827http://support.citrix.com/article/CTX136163http://www.securityfocus.com/bid/57225http://www.securityfocus.com/bid/57259http://www.securitytracker.com/id?1027978
2013-01-22
Published