Lucene search

K
cvelistRedhatCVELIST:CVE-2017-2614
HistoryJul 27, 2018 - 6:00 p.m.

CVE-2017-2614

2018-07-2718:00:00
CWE-20
redhat
www.cve.org
7

CVSS3

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0

Percentile

12.6%

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.

CNA Affected

[
  {
    "product": "ovirt-engine-extension-aaa-jdbc",
    "vendor": "Red Hat",
    "versions": [
      {
        "status": "affected",
        "version": "1.1.3"
      }
    ]
  }
]

CVSS3

6.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

AI Score

6.3

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2017-2614