CVE-2016-7071

CWE-2855 documents5 sources
Severity
8.8HIGH
EPSS
0.5%
top 35.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateMay 13

Description

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDredhat/cloudforms_management_engine5.7.0.05.7.0.7+1
CVEListV5red_hat/cfme5.6.2.2, 5.7.0.7+1

🔴Vulnerability Details

2
GHSA
GHSA-82ph-q482-5fhg: It was found that the CloudForms before 52022-05-13
CVEList
CVE-2016-7071: It was found that the CloudForms before 52018-09-10

📋Vendor Advisories

1
Red Hat
CFME: bypass authorization by altering VM ID2016-10-20

💬Community

1
Bugzilla
CVE-2016-7071 CFME: bypass authorization by altering VM ID2016-10-10
CVE-2016-7071 (HIGH CVSS 8.8) | It was found that the CloudForms be | cvebase.io