CVE-2014-0140

Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms_3.0.1_management_engine:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0.2_management_engine:5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0.3_management_engine:5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0.4_management_engine:5.2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0.5_management_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0_management_engine:5.2:*:*:*:*:*:*:*

History

13 Feb 2023, 00:32

Type Values Removed Values Added
Summary It was found that Red Hat CloudForms exposed default routes that were reachable via HTTP(S) requests. An authenticated user could use this flaw to access potentially sensitive controllers and actions that would allow for privilege escalation. Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:1317', 'name': 'https://access.redhat.com/errata/RHSA-2014:1317', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-0140', 'name': 'https://access.redhat.com/security/cve/CVE-2014-0140', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 16:15

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2014:1317 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-0140 -
Summary Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request. It was found that Red Hat CloudForms exposed default routes that were reachable via HTTP(S) requests. An authenticated user could use this flaw to access potentially sensitive controllers and actions that would allow for privilege escalation.

Information

Published : 2014-10-06 14:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-0140

Mitre link : CVE-2014-0140

CVE.ORG link : CVE-2014-0140


JSON object : View

Products Affected

redhat

  • cloudforms_3.0.2_management_engine
  • cloudforms_3.0.3_management_engine
  • cloudforms_3.0_management_engine
  • cloudforms_3.0.1_management_engine
  • cloudforms_3.0.5_management_engine
  • cloudforms_3.0.4_management_engine
CWE
CWE-264

Permissions, Privileges, and Access Controls