Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Enterprise_virtualization
(Redhat)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 36 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2014-12-05 | CVE-2014-3561 | The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes. | Enterprise_virtualization | N/A | ||
2016-10-03 | CVE-2016-5432 | The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files. | Enterprise_virtualization | 3.3 | ||
2016-12-14 | CVE-2016-4443 | Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file. | Enterprise_virtualization | 5.5 | ||
2017-04-20 | CVE-2016-6338 | ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors related to UI selections, which trigger repeating queries. | Enterprise_virtualization | 6.8 | ||
2018-05-17 | CVE-2018-1111 | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol. | Fedora, Enterprise_linux, Enterprise_linux_desktop, Enterprise_linux_server, Enterprise_linux_workstation, Enterprise_virtualization, Enterprise_virtualization_host | 7.5 | ||
2020-02-25 | CVE-2015-5201 | VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors. | Enterprise_virtualization, Enterprise_virtualization_hypervisor | 7.5 | ||
2019-11-13 | CVE-2014-8167 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack | Enterprise_virtualization, Vdsclient, Virtual_desktop_server_manager | N/A | ||
2018-04-26 | CVE-2018-1074 | ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control. | Ovirt, Enterprise_virtualization | 7.2 | ||
2019-11-04 | CVE-2013-4280 | Insecure temporary file vulnerability in RedHat vsdm 4.9.6. | Enterprise_virtualization, Storage, Virtual_desktop_server_manager | N/A | ||
2018-06-20 | CVE-2018-1117 | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation. | Ovirt\-Ansible\-Roles, Enterprise_virtualization | 9.8 |