ZeroHour

CVE-2017-7530

CVSS 3.0
8.8 high
EPSS
2%p76
Published
()
Modified
Description

In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users. An attacker could use this to execute actions they should not be allowed to (e.g. destroying VMs).

Vendors
redhat
Products
cloudforms, cloudforms management engine
Weakness
CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.