CVE-2014-0140

CWE-264CWE-7495 documents5 sources
Severity
4.0MEDIUM
EPSS
0.2%
top 61.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 6
Latest updateMay 17

Description

Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 8.0 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-97hc-8rcf-x5ph: Red Hat CloudForms 32022-05-17
CVEList
CVE-2014-0140: Red Hat CloudForms 32014-10-06

📋Vendor Advisories

1
Red Hat
CFME: default routes expose controllers and actions2014-10-02

💬Community

1
Bugzilla
CVE-2014-0140 CFME: default routes expose controllers and actions2014-03-17