CVE-2014-0137

CWE-89SQL Injection6 documents5 sources
Severity
6.5MEDIUM
EPSS
0.4%
top 39.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 17

Description

SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-vc39-w9gh-6rx2: SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 52022-05-17
CVEList
CVE-2014-0137: SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 52014-05-14

📋Vendor Advisories

1
Red Hat
CFME: ReportController SQL injection2014-05-12

💬Community

2
Bugzilla
CVE-2014-0137 CFME: ReportController SQL injection2014-03-14
Bugzilla
CVE-2014-0497 flash-plugin: integer underflow flaw leads to arbitrary code execution (APSB14-04)2014-02-04