CVE-2016-4443

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2016-1929.html Mitigation Patch Vendor Advisory
http://www.securityfocus.com/bid/92751 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1036863 Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1335106 Issue Tracking VDB Entry Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:enterprise_virtualization:3.6:*:*:*:*:*:*:*

History

12 Feb 2023, 23:20

Type Values Removed Values Added
Summary A flaw was found in RHEV Manager, where it wrote sensitive data to the engine-setup log file. A local attacker could exploit this flaw to view sensitive information such as encryption keys and certificates (which could then be used to steal other sensitive information such as passwords). Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2016:1929', 'name': 'https://access.redhat.com/errata/RHSA-2016:1929', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-4443', 'name': 'https://access.redhat.com/security/cve/CVE-2016-4443', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 15:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2016:1929 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-4443 -
Summary Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file. A flaw was found in RHEV Manager, where it wrote sensitive data to the engine-setup log file. A local attacker could exploit this flaw to view sensitive information such as encryption keys and certificates (which could then be used to steal other sensitive information such as passwords).

Information

Published : 2016-12-14 18:59

Updated : 2023-12-10 12:01


NVD link : CVE-2016-4443

Mitre link : CVE-2016-4443

CVE.ORG link : CVE-2016-4443


JSON object : View

Products Affected

redhat

  • enterprise_virtualization
CWE
CWE-532

Insertion of Sensitive Information into Log File