CVE-2016-4455

Severity
3.3LOW
EPSS
0.0%
top 85.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 13

Description

The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages5 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q3jw-m6vv-gg29: The Subscription Manager package (aka subscription-manager) before 12022-05-13
CVEList
CVE-2016-4455: The Subscription Manager package (aka subscription-manager) before 12017-04-14

📋Vendor Advisories

1
Red Hat
subscription-manager: sensitive world readable files in /var/lib/rhsm/2016-05-25

💬Community

1
Bugzilla
CVE-2016-4455 subscription-manager: sensitive world readable files in /var/lib/rhsm/2016-05-27