CVE-2014-3642
published 2014-10-06CVE-2014-3642: vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to…
PriorityP430medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.29%
66.9th percentile
vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | netscaler_adc_gateway | — | — |
| redhat | cloudforms_3.0.1_management_engine | — | — |
| redhat | cloudforms_3.0.2_management_engine | — | — |
| redhat | cloudforms_3.0.3_management_engine | — | — |
| redhat | cloudforms_3.0.4_management_engine | — | — |
| redhat | cloudforms_3.0.5_management_engine | <= 5.2.5 | — |
| redhat | cloudforms_3.0_management_engine | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2015-3642: The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x be
vendor_citrix·2017-08-02·CVSS 5.9
CVE-2015-3642 [LOW] CWE-200 CVE-2015-3642: The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x be
CVE-2015-3642: The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
Red Hat
CFME: dangerous send method in performance.rb
vendor_redhat·2014-10-02·CVSS 6.5
CVE-2014-3642 [MEDIUM] CWE-470 CFME: dangerous send method in performance.rb
CFME: dangerous send method in performance.rb
vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."
It was found that Red Hat CloudForms contained an insecure send method that accepted user-supplied arguments. An authenticated user could use this flaw to modify the program flow in a way that could result in privilege escalation.
GHSA
GHSA-xjwp-9jvp-98jf: vmdb/app/controllers/application_controller/performance
ghsa_unreviewed·2022-05-17
CVE-2014-3642 [MEDIUM] GHSA-xjwp-9jvp-98jf: vmdb/app/controllers/application_controller/performance
vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."
No detection rules found.
No public exploits indexed.
2014-10-06
Published