CVE-2015-0237
published 2015-05-01CVE-2015-0237: Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains…
PriorityP426medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
1.59%
72.8th percentile
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | <= 3.5.0 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w75w-f8r5-wc7w: Red Hat Enterprise Virtualization (RHEV) Manager before 3
ghsa_unreviewed·2022-05-17
CVE-2015-0237 [MEDIUM] GHSA-w75w-f8r5-wc7w: Red Hat Enterprise Virtualization (RHEV) Manager before 3
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain.
Red Hat
vdsm: Users attempting a live storage migration create snapshot without snapshot creation permissions
vendor_redhat·2015-02-04·CVSS 6.8
CVE-2015-0237 [MEDIUM] CWE-732 vdsm: Users attempting a live storage migration create snapshot without snapshot creation permissions
vdsm: Users attempting a live storage migration create snapshot without snapshot creation permissions
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain.
It was discovered that the permissions to allow or deny snapshot creation were ignored during live storage migration of a VM's disk between storage domains. An attacker able to live migrate a disk between storage domains could use this flaw to cause a denial of service.
Statement: This issue affects the versions of ovirt-engine-backend as shipped with Red Hat Enterprise Virtualization 3. Red Hat Product Secur
No detection rules found.
No public exploits indexed.
2015-05-01
Published