CVE-2016-5432

The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:redhat:enterprise_virtualization:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

History

12 Feb 2023, 23:24

Type Values Removed Values Added
Summary It was found that the ovirt-engine-provisiondb utility did not correctly sanitize the authentication details used with the “—provision*db” options from the output before storing them in log files. This could allow an attacker with read access to these log files to obtain sensitive information such as passwords. The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-5432', 'name': 'https://access.redhat.com/security/cve/CVE-2016-5432', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2016:1967', 'name': 'https://access.redhat.com/errata/RHSA-2016:1967', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 16:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-5432 -
  • (MISC) https://access.redhat.com/errata/RHSA-2016:1967 -
Summary The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files. It was found that the ovirt-engine-provisiondb utility did not correctly sanitize the authentication details used with the “—provision*db” options from the output before storing them in log files. This could allow an attacker with read access to these log files to obtain sensitive information such as passwords.

Information

Published : 2016-10-03 18:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-5432

Mitre link : CVE-2016-5432

CVE.ORG link : CVE-2016-5432


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • enterprise_virtualization
CWE
CWE-532

Insertion of Sensitive Information into Log File