Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Enterprise_virtualization
(Redhat)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 36 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-13 | CVE-2014-8167 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack | Enterprise_virtualization, Vdsclient, Virtual_desktop_server_manager | N/A | ||
2018-04-26 | CVE-2018-1074 | ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control. | Ovirt, Enterprise_virtualization | 7.2 | ||
2019-11-04 | CVE-2013-4280 | Insecure temporary file vulnerability in RedHat vsdm 4.9.6. | Enterprise_virtualization, Storage, Virtual_desktop_server_manager | N/A | ||
2018-06-20 | CVE-2018-1117 | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation. | Ovirt\-Ansible\-Roles, Enterprise_virtualization | 9.8 | ||
2018-07-27 | CVE-2017-2614 | When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts. | Enterprise_virtualization | 6.3 | ||
2017-08-22 | CVE-2016-6310 | oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0. | Enterprise_virtualization | 5.5 | ||
2015-09-08 | CVE-2015-1841 | The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view. | Enterprise_virtualization | N/A | ||
2014-08-03 | CVE-2014-5177 | libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10)... | Opensuse, Enterprise_linux, Enterprise_virtualization, Libvirt | N/A | ||
2013-08-28 | CVE-2013-2176 | Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan horse application. | Enterprise_virtualization | N/A | ||
2014-01-21 | CVE-2013-2152 | Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder. | Enterprise_virtualization | N/A |