CVE-2015-0257Insufficiently Protected Credentials in Redhat Enterprise Virtualization Manager

Severity
2.1LOWNVD
EPSS
0.0%
top 87.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateMay 17

Description

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-7944-mp99-q983: Red Hat Enterprise Virtualization (RHEV) Manager before 32022-05-17
CVEList
CVE-2015-0257: Red Hat Enterprise Virtualization (RHEV) Manager before 32015-05-01

📋Vendor Advisories

1
Red Hat
ovirt-engine-dwh: incorrect permissions on plugin file containing passwords2015-01-04

💬Community

1
Bugzilla
CVE-2015-0257 ovirt-engine-dwh: incorrect permissions on plugin file containing passwords2015-02-04