CVE-2014-0078

The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to delete arbitrary catalogs via vectors involving guessing the catalog ID.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms_3.0_management_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0_management_engine:5.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0_management_engine:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0_management_engine:5.2.2:*:*:*:*:*:*:*

History

13 Feb 2023, 00:31

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-0078', 'name': 'https://access.redhat.com/security/cve/CVE-2014-0078', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0469', 'name': 'https://access.redhat.com/errata/RHSA-2014:0469', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2014-0078 CFME: multiple authorization bypass vulnerabilities in CatalogController The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to delete arbitrary catalogs via vectors involving guessing the catalog ID.

02 Feb 2023, 20:16

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-0078 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0469 -
Summary The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to delete arbitrary catalogs via vectors involving guessing the catalog ID. CVE-2014-0078 CFME: multiple authorization bypass vulnerabilities in CatalogController

Information

Published : 2014-05-14 19:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-0078

Mitre link : CVE-2014-0078

CVE.ORG link : CVE-2014-0078


JSON object : View

Products Affected

redhat

  • cloudforms_3.0_management_engine
CWE
CWE-264

Permissions, Privileges, and Access Controls