CVE-2014-0140
published 2014-10-06CVE-2014-0140: Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or…
PriorityP418medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.24%
65.7th percentile
Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms_3.0.1_management_engine | — | — |
| redhat | cloudforms_3.0.2_management_engine | — | — |
| redhat | cloudforms_3.0.3_management_engine | — | — |
| redhat | cloudforms_3.0.4_management_engine | — | — |
| redhat | cloudforms_3.0.5_management_engine | <= 5.2.5 | — |
| redhat | cloudforms_3.0_management_engine | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-97hc-8rcf-x5ph: Red Hat CloudForms 3
ghsa_unreviewed·2022-05-17
CVE-2014-0140 [MEDIUM] GHSA-97hc-8rcf-x5ph: Red Hat CloudForms 3
Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.
Red Hat
CFME: default routes expose controllers and actions
vendor_redhat·2014-10-02·CVSS 4.0
CVE-2014-0140 [MEDIUM] CWE-749 CFME: default routes expose controllers and actions
CFME: default routes expose controllers and actions
Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.
It was found that Red Hat CloudForms exposed default routes that were reachable via HTTP(S) requests. An authenticated user could use this flaw to access potentially sensitive controllers and actions that would allow for privilege escalation.
No detection rules found.
No public exploits indexed.
2014-10-06
Published