CVE-2012-4501

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:cloudstack:-:prerelease:*:*:*:*:*:*
cpe:2.3:a:citrix:cloudstack:-:*:*:*:*:*:*:*

Information

Published : 2012-10-26 03:39

Updated : 2012-10-26 10:08


NVD link : CVE-2012-4501

Mitre link : CVE-2012-4501


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

apache

  • cloudstack

citrix

  • cloudstack