The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1371428 | Issue Tracking Patch Vendor Advisory |
http://rhn.redhat.com/errata/RHSA-2016-1967.html | Vendor Advisory |
https://gerrit.ovirt.org/#/q/I40c88ad48f8f7c2b8e06802137870b0c198b5129 | Patch |
http://www.securityfocus.com/bid/92694 |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2016-10-03 11:59
Updated : 2023-02-12 15:24
NVD link : CVE-2016-5432
Mitre link : CVE-2016-5432
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
redhat
- enterprise_virtualization
- enterprise_linux