CVE-2015-7544
published 2017-09-25CVE-2015-7544: redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role…
PriorityP353critical9.1CVSS 3.0
AVNACLPRHUINSCCHIHAH
EPSS
3.44%
87.6th percentile
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3v3-p323-g553: redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3
ghsa_unreviewed·2022-05-17
CVE-2015-7544 [CRITICAL] CWE-74 GHSA-w3v3-p323-g553: redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
Red Hat
redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV
vendor_redhat·2015-12-07·CVSS 9.1
CVE-2015-7544 [CRITICAL] CWE-20 redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV
redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
It was found that redhat-support-plugin-rhev passed a user-specified path and file name directly to the command line in the log viewer component. This could allow users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
No detection rules found.
No public exploits indexed.
2017-09-25
Published