CVE-2018-0336
published 2018-06-07CVE-2018-0336: A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate…
PriorityP356high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.42%
82.2th percentile
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulnerability is due to insufficient authorization enforcement on batch processing. An attacker could exploit this vulnerability by uploading a batch file and having the batch file processed by the system. A successful exploit could allow the attacker to escalate privileges to the Administrator level. Cisco Bug IDs: CSCvd86578.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration | — | — |
| cisco | prime_collaboration_provisioning | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Provisioning Access Control Deficiency in Batch Function Privilege Escalation Vulnerability
vendor_cisco·2018-06-06·CVSS 5.3
CVE-2018-0336 [MEDIUM] CWE-264 Cisco Prime Collaboration Provisioning Access Control Deficiency in Batch Function Privilege Escalation Vulnerability
Cisco Prime Collaboration Provisioning Access Control Deficiency in Batch Function Privilege Escalation Vulnerability
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level.
The vulnerability is due to insufficient authorization enforcement on batch processing. An attacker could exploit this vulnerability by uploading a batch file and having the batch file processed by the system. A successful exploit could allow the attacker to escalate privileges to the Administrator level.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisor
Cisco
Cisco Prime Collaboration Provisioning Access Control Deficiency in Batch Function Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0336 Cisco Prime Collaboration Provisioning Access Control Deficiency in Batch Function Privilege Escalation Vulnerability
CVE-2018-0336: Cisco Prime Collaboration Provisioning Access Control Deficiency in Batch Function Privilege Escalation Vulnerability
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulnerability is due to insufficient authorization enforcement on batch processing. An attacker could exploit this vulnerability by uploading a batch file and having the batch file processed by the system. A successful exploit could allow the attacker to escalate privileges to the Administrator level. There are no
CVSS: 3.0
CWE: CWE-264, CWE-264
Bug IDs: CSCvd86578
GHSA
GHSA-2cmf-8qcc-8v59: A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate
ghsa_unreviewed·2022-05-13
CVE-2018-0336 [HIGH] CWE-862 GHSA-2cmf-8qcc-8v59: A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate
A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulnerability is due to insufficient authorization enforcement on batch processing. An attacker could exploit this vulnerability by uploading a batch file and having the batch file processed by the system. A successful exploit could allow the attacker to escalate privileges to the Administrator level. Cisco Bug IDs: CSCvd86578.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8183 foreman: models with a 'belongs_to' association to an Organization do not verify association belongs to that Organization
bugzilla·2017-08-12·CVSS 7.4
CVE-2014-8183 [HIGH] CVE-2014-8183 foreman: models with a 'belongs_to' association to an Organization do not verify association belongs to that Organization
CVE-2014-8183 foreman: models with a 'belongs_to' association to an Organization do not verify association belongs to that Organization
Eric Helms of Red Hat reports:
Users can access resources in other organizations via the API if they can guess the name of the resource as access restrictions are not properly enforced.
Discussion:
Acknowledgments:
Name: Eric Helms (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
Bugzilla
CVE-2017-2672 foreman: Image password leak
bugzilla·2017-04-06·CVSS 6.5
CVE-2017-2672 [MEDIUM] CVE-2017-2672 foreman: Image password leak
CVE-2017-2672 foreman: Image password leak
When images for compute resources (e.g. an OpenStack image) are added/registered in Foreman, the password used to log in is recorded in plain text in the audit log. This may allow users with access to view the audit log to access newly provisioned hosts using the stored credentials.
Upstream bug:
http://projects.theforeman.org/issues/19169
Discussion:
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
Bugzilla
CVE-2017-2667 rubygem-hammer_cli: no verification of API server's SSL certificate
bugzilla·2017-03-27·CVSS 8.1
CVE-2017-2667 [HIGH] CVE-2017-2667 rubygem-hammer_cli: no verification of API server's SSL certificate
CVE-2017-2667 rubygem-hammer_cli: no verification of API server's SSL certificate
Tomas Strachota of Red Hat reports:
It was found that Hammer CLI, a CLI utility for Foreman, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Upstream issue:
http://projects.theforeman.org/issues/19033
Discussion:
Acknowledgments:
Name: Tomas Strachota (Red Hat)
---
openstack 6 foreman installer is EOL
---
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
---
Statement:
This issue affects the versions of rubygem-hammer_cli as shipped with Re
Bugzilla
CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name
bugzilla·2016-11-09·CVSS 6.1
CVE-2016-8639 [MEDIUM] CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name
CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name
Sanket Jagtap of Red Hat reports:
If an organization or location is created with a name containing HTML,
then the administrator-only Settings page will render the HTML as part
of a dropdown menu.
This may permit a stored XSS attack if an organization/location with
HTML in the name is created, then an administrator attempts to change
the default organization/location settings.
Upstream bug:
http://projects.theforeman.org/issues/15037
Upstream patch:
https://github.com/theforeman/foreman/pull/3523
Discussion:
Acknowledgments:
Name: Sanket Jagtap (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RH
Bugzilla
CVE-2016-6319 foreman: Persistent XSS in Foreman remote execution plugin
bugzilla·2016-08-10·CVSS 6.1
CVE-2016-6319 [MEDIUM] CVE-2016-6319 foreman: Persistent XSS in Foreman remote execution plugin
CVE-2016-6319 foreman: Persistent XSS in Foreman remote execution plugin
Marek Hulán of Red Hat reports:
User can define a job template and specify input name containing JS code. When
someone tries to invoke such job, the form is generated based on this name
without proper escaping so the JS gets executed.
Upstream issue:
http://projects.theforeman.org/issues/16019
Proposed upstream patch:
https://github.com/theforeman/foreman/pull/3715/commits/4b63d2c7cdad76ed2bf96d9f8dff7e0c5cdabda6
Discussion:
Acknowledgments:
Name: Marek Hulán (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
http://www.securityfocus.com/bid/104429http://www.securitytracker.com/id/1041083https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-escalationhttp://www.securityfocus.com/bid/104429http://www.securitytracker.com/id/1041083https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-prime-escalation
2018-06-07
Published