CVE-2014-0078

Severity
4.0MEDIUM
EPSS
0.6%
top 30.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 17

Description

The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to delete arbitrary catalogs via vectors involving guessing the catalog ID.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-fxwq-pp2x-ch5j: The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5โ†—2022-05-17
โ–ถ
CVEList
CVE-2014-0078: The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5โ†—2014-05-14
โ–ถ

๐Ÿ“‹Vendor Advisories

1
Red Hat
CFME: multiple authorization bypass vulnerabilities in CatalogControllerโ†—2014-05-12
โ–ถ

๐Ÿ’ฌCommunity

1
Bugzilla
CVE-2014-0078 CFME: multiple authorization bypass vulnerabilities in CatalogControllerโ†—2014-02-12
โ–ถ