CVE-2016-5383
published 2016-08-26CVE-2016-5383: The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
PriorityP352high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.63%
83.8th percentile
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CloudForms: Lack of field filters on user input
vendor_redhat·2016-08-18·CVSS 8.8
CVE-2016-5383 [HIGH] CWE-20 CloudForms: Lack of field filters on user input
CloudForms: Lack of field filters on user input
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
It was found that the CloudForms web UI did not properly filter input in certain fields. A remote, authenticated attacker could use this flaw to execute arbitrary code on the system running CloudForms.
GHSA
GHSA-8vfr-r3m3-8998: The web UI in Red Hat CloudForms 4
ghsa_unreviewed·2022-05-17
CVE-2016-5383 [HIGH] CWE-284 GHSA-8vfr-r3m3-8998: The web UI in Red Hat CloudForms 4
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
No detection rules found.
No public exploits indexed.
2016-08-26
Published