CVE-2016-4443
published 2016-12-14CVE-2016-4443: Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the…
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.24%
14.3th percentile
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.ovirt.engine-root: engine-setup logs contained information for extracting admin password
vendor_redhat·2016-09-02·CVSS 5.5
CVE-2016-4443 [MEDIUM] CWE-532 org.ovirt.engine-root: engine-setup logs contained information for extracting admin password
org.ovirt.engine-root: engine-setup logs contained information for extracting admin password
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
A flaw was found in RHEV Manager, where it wrote sensitive data to the engine-setup log file. A local attacker could exploit this flaw to view sensitive information such as encryption keys and certificates (which could then be used to steal other sensitive information such as passwords).
Package: org.ovirt.engine-root (Red Hat Gluster Storage 3.1) - Will not fix
GHSA
GHSA-crrm-jp94-w9fv: Red Hat Enterprise Virtualization (RHEV) Manager 3
ghsa_unreviewed·2022-05-17
CVE-2016-4443 [MEDIUM] CWE-532 GHSA-crrm-jp94-w9fv: Red Hat Enterprise Virtualization (RHEV) Manager 3
Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-1929.htmlhttp://www.securityfocus.com/bid/92751http://www.securitytracker.com/id/1036863https://bugzilla.redhat.com/show_bug.cgi?id=1335106http://rhn.redhat.com/errata/RHSA-2016-1929.htmlhttp://www.securityfocus.com/bid/92751http://www.securitytracker.com/id/1036863https://bugzilla.redhat.com/show_bug.cgi?id=1335106
2016-12-14
Published