CVE-2016-5402
published 2018-10-31CVE-2016-5402: A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the…
PriorityP357high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
5.93%
92.4th percentile
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms | — | — |
| redhat | cloudforms_management_engine | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cfme: RCE via Capacity & Utilization feature
vendor_redhat·2016-11-30·CVSS 8.8
CVE-2016-5402 [HIGH] CWE-94 cfme: RCE via Capacity & Utilization feature
cfme: RCE via Capacity & Utilization feature
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
GHSA
GHSA-6p9p-cwcr-3xj6: A code injection flaw was found in the way capacity and utilization imported control files are processed
ghsa_unreviewed·2022-05-13
CVE-2016-5402 [HIGH] CWE-94 GHSA-6p9p-cwcr-3xj6: A code injection flaw was found in the way capacity and utilization imported control files are processed
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
No detection rules found.
No public exploits indexed.
2018-10-31
Published