CVE-2016-7047

Severity
4.3MEDIUM
EPSS
0.3%
top 44.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 13

Description

A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDredhat/cloudforms4.2, 4.5+1
CVEListV5red_hat/cfme5.6.3.0, 5.7.3.1, 5.8.1.2+2

🔴Vulnerability Details

2
GHSA
GHSA-2499-9m7g-hrw5: A flaw was found in the CloudForms API before 52022-05-13
CVEList
CVE-2016-7047: A flaw was found in the CloudForms API before 52018-09-11

📋Vendor Advisories

1
Red Hat
cfme: API leaks any MiqReportResult2017-06-28

💬Community

1
Bugzilla
CVE-2016-7047 cfme: API leaks any MiqReportResult2016-09-08
CVE-2016-7047 (MEDIUM CVSS 4.3) | A flaw was found in the CloudForms | cvebase.io