CVE-2014-0057

Severity
7.5HIGH
EPSS
0.7%
top 27.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 17

Description

The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remote attackers to execute arbitrary methods via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-6m4c-55qp-f477: The x_button method in the ServiceController (vmdb/app/controllers/service_controller2022-05-17
CVEList
CVE-2014-0057: The x_button method in the ServiceController (vmdb/app/controllers/service_controller2014-03-18

📋Vendor Advisories

1
Red Hat
CFME: Dangerous send in ServiceController2014-03-11

💬Community

1
Bugzilla
CVE-2014-0057 CFME: Dangerous send in ServiceController2014-02-12