CVE-2016-7047

A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:4.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*

Information

Published : 2018-09-11 06:29

Updated : 2019-10-09 16:19


NVD link : CVE-2016-7047

Mitre link : CVE-2016-7047


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

redhat

  • cloudforms_management_engine
  • cloudforms