CVE-2016-7071
published 2018-09-10CVE-2016-7071: It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated…
PriorityP352high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.20%
80.5th percentile
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | cfme | — | — |
| red_hat | cfme | — | — |
| redhat | cloudforms | — | — |
| redhat | cloudforms_management_engine | < 5.6.2.2 | 5.6.2.2 |
| redhat | cloudforms_management_engine | >= 5.7.0.0 < 5.7.0.7 | 5.7.0.7 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CFME: bypass authorization by altering VM ID
vendor_redhat·2016-10-20·CVSS 8.8
CVE-2016-7071 [HIGH] CWE-285 CFME: bypass authorization by altering VM ID
CFME: bypass authorization by altering VM ID
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.
It was found that the CloudForms did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.
GHSA
GHSA-82ph-q482-5fhg: It was found that the CloudForms before 5
ghsa_unreviewed·2022-05-13
CVE-2016-7071 [HIGH] CWE-285 GHSA-82ph-q482-5fhg: It was found that the CloudForms before 5
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.
No detection rules found.
No public exploits indexed.
2018-09-10
Published