CVE-2017-2614
published 2018-07-27CVE-2017-2614: When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired…
PriorityP428medium6.3CVSS 3.0
AVLACLPRLUINSCCLILAL
EPSS
0.28%
20.0th percentile
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | ovirt-engine-extension-aaa-jdbc | — | — |
| redhat | enterprise_virtualization | — | — |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w5vv-xfcc-x3jc: When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1
ghsa_unreviewed·2022-05-13
CVE-2017-2614 [MEDIUM] CWE-640 GHSA-w5vv-xfcc-x3jc: When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
Red Hat
rhev-m-4: Fails to validate existing expired passwords when changing a password
vendor_redhat·2017-02-06·CVSS 6.8
CVE-2017-2614 [MEDIUM] CWE-20 rhev-m-4: Fails to validate existing expired passwords when changing a password
rhev-m-4: Fails to validate existing expired passwords when changing a password
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.
No detection rules found.
No public exploits indexed.
2018-07-27
Published