ZeroHour

CVE-2016-5402

CVSS 3.0
8.8 high
EPSS
6%p93
Published
()
Modified
Description

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

Vendors
redhat
Products
cloudforms, cloudforms management engine
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.