CVE-2014-0136
published 2014-10-27CVE-2014-0136: The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.57%
72.5th percentile
The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms_3.0_management_engine | <= 5.2.5.3 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CFME: AgentController get/log application log forging
vendor_redhat·2014-08-13·CVSS 5.0
CVE-2014-0136 [MEDIUM] CWE-117 CFME: AgentController get/log application log forging
CFME: AgentController get/log application log forging
The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.
It was found that the get and log methods of the AgentController wrote log messages without sanitizing user input. A remote attacker could use this flaw to insert arbitrary content into the log files written to by AgentController.
GHSA
GHSA-xf8w-qcq9-6w6f: The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3
ghsa_unreviewed·2022-05-17
CVE-2014-0136 [MEDIUM] CWE-20 GHSA-xf8w-qcq9-6w6f: The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3
The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0136 CFME: AgentController get/log application log forging
bugzilla·2014-03-14·CVSS 5.0
CVE-2014-0136 [MEDIUM] CVE-2014-0136 CFME: AgentController get/log application log forging
CVE-2014-0136 CFME: AgentController get/log application log forging
IssueDescription:
It was found that the get and log methods of the AgentController wrote log messages without sanitizing user input. A remote attacker could use this flaw to insert arbitrary content into the log files written to by AgentController.
Acknowledgement:
This issue was discovered by Jan Rusnacko of Red Hat Product Security.
Discussion:
Jan Rusnacko was able to execute this without authentication, updated CVSS2 score.
---
This issue has been addressed in following products:
CloudForms Management Engine 5.x
Via RHSA-2014:1037 https://rhn.redhat.com/errata/RHSA-2014-1037.html
Bugzilla
CVE-2014-0417 Oracle JDK: unspecified vulnerability fixed in 5.0u71, 6u71 and 7u51 (2D)
bugzilla·2014-01-15·CVSS 9.3
CVE-2014-0417 [CRITICAL] CVE-2014-0417 Oracle JDK: unspecified vulnerability fixed in 5.0u71, 6u71 and 7u51 (2D)
CVE-2014-0417 Oracle JDK: unspecified vulnerability fixed in 5.0u71, 6u71 and 7u51 (2D)
Oracle Java SE 5.0u71, 6u71 and 7u51 fixes an unspecified vulnerability in the 2D component (CVE-2014-0417). Upstream has CVSSv2 scored this issue as: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0030 https://rhn.redhat.com/errata/RHSA-2014-0030.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0136 https://rhn.redhat.com
2014-10-27
Published