cbcvebase.
CVE-2017-2614
published 2018-07-27

CVE-2017-2614: When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired…

PriorityP428medium6.3CVSS 3.0
AVLACLPRLUINSCCLILAL
EPSS
0.28%
20.0th percentile
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.

Affected

2 ranges
VendorProductVersion rangeFixed in
red_hatovirt-engine-extension-aaa-jdbc
redhatenterprise_virtualization

CVSS provenance

nvdv3.06.3MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.