CVE-2017-2664

Severity
6.5MEDIUM
EPSS
0.2%
top 55.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 26
Latest updateMay 13

Description

CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDredhat/cloudforms4.2, 4.6+1
CVEListV5red_hat/cloudforms5.7.3, 5.8.1+1

🔴Vulnerability Details

2
GHSA
GHSA-rc49-fxf8-jgg2: CloudForms Management Engine (cfme) before 52022-05-13
CVEList
CVE-2017-2664: CloudForms Management Engine (cfme) before 52018-07-26

📋Vendor Advisories

1
Red Hat
CloudForms: lack of RBAC on various methods in web UI2017-08-02

💬Community

2
Bugzilla
CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI2017-03-23
Bugzilla
CVE-2017-5563 libtiff: Heap-buffer overflow in LZWEncode tif_lzw.c2017-01-24
CVE-2017-2664 (MEDIUM CVSS 6.5) | CloudForms Management Engine (cfme) | cvebase.io