CVE-2015-0257
published 2015-05-01CVE-2015-0257: Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.38%
30.4th percentile
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | <= 3.5.0 | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7944-mp99-q983: Red Hat Enterprise Virtualization (RHEV) Manager before 3
ghsa_unreviewed·2022-05-17
CVE-2015-0257 [LOW] GHSA-7944-mp99-q983: Red Hat Enterprise Virtualization (RHEV) Manager before 3
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.
Red Hat
ovirt-engine-dwh: incorrect permissions on plugin file containing passwords
vendor_redhat·2015-01-04·CVSS 2.1
CVE-2015-0257 [LOW] CWE-522 ovirt-engine-dwh: incorrect permissions on plugin file containing passwords
ovirt-engine-dwh: incorrect permissions on plugin file containing passwords
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.
It was discovered that a directory shared between the ovirt-engine-dwhd service and a plug-in used during the service's startup had incorrect permissions. A local user could use this flaw to access files in this directory, which could potentially contain sensitive information.
No detection rules found.
No public exploits indexed.
2015-05-01
Published