CVE-2015-7502
published 2016-04-11CVE-2015-7502: Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL…
PriorityP421medium5.1CVSS 3.0
AVLACHPRNUINSUCHINAN
EPSS
0.34%
26.2th percentile
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms | — | — |
| redhat | cloudforms | — | — |
| redhat | cloudforms_management_engine | — | — |
| redhat | cloudforms_management_engine | — | — |
CVSS provenance
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vhf3-65mf-c545: Red Hat CloudForms 3
ghsa_unreviewed·2022-05-17
CVE-2015-7502 [MEDIUM] CWE-200 GHSA-vhf3-65mf-c545: Red Hat CloudForms 3
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.
Red Hat
CloudForms: insecure password storage in PostgreSQL database
vendor_redhat·2015-11-18·CVSS 5.1
CVE-2015-7502 [MEDIUM] CWE-522 CloudForms: insecure password storage in PostgreSQL database
CloudForms: insecure password storage in PostgreSQL database
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.
A privilege escalation flaw was discovered in CloudForms, where in certain situations, CloudForms could read encrypted data from the database and then write decrypted data back into the database. If the database was then exported or log files generated, a local attacker might be able to gain access to sensitive information.
No detection rules found.
No public exploits indexed.
2016-04-11
Published