CVE-2017-7530

In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users. An attacker could use this to execute actions they should not be allowed to (e.g. destroying VMs).
References
Link Resource
http://www.securityfocus.com/bid/100151 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:1758 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7530 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-26 13:29

Updated : 2023-12-10 12:44


NVD link : CVE-2017-7530

Mitre link : CVE-2017-7530

CVE.ORG link : CVE-2017-7530


JSON object : View

Products Affected

redhat

  • cloudforms_management_engine
  • cloudforms
CWE
NVD-CWE-noinfo CWE-862

Missing Authorization