CVE-2016-5432
published 2016-10-03CVE-2016-5432: The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning…
PriorityP48low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.35%
26.7th percentile
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ovirt-engine: ovirt-engine-provisiondb logs contain DB username and password in plain text
vendor_redhat·2016-08-30·CVSS 3.3
CVE-2016-5432 [LOW] CWE-312 ovirt-engine: ovirt-engine-provisiondb logs contain DB username and password in plain text
ovirt-engine: ovirt-engine-provisiondb logs contain DB username and password in plain text
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
It was found that the ovirt-engine-provisiondb utility did not correctly sanitize the authentication details used with the “—provision*db” options from the output before storing them in log files. This could allow an attacker with read access to these log files to obtain sensitive information such as passwords.
Package: ovirt-engine (Red Hat Enterprise Virtualization 3) - Will not fix
GHSA
GHSA-8pc7-rggg-xw6r: The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4
ghsa_unreviewed·2022-05-17
CVE-2016-5432 [LOW] CWE-532 GHSA-8pc7-rggg-xw6r: The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-1967.htmlhttp://www.securityfocus.com/bid/92694https://bugzilla.redhat.com/show_bug.cgi?id=1371428https://gerrit.ovirt.org/#/q/I40c88ad48f8f7c2b8e06802137870b0c198b5129http://rhn.redhat.com/errata/RHSA-2016-1967.htmlhttp://www.securityfocus.com/bid/92694https://bugzilla.redhat.com/show_bug.cgi?id=1371428https://gerrit.ovirt.org/#/q/I40c88ad48f8f7c2b8e06802137870b0c198b5129
2016-10-03
Published