CVSS2
Attack Vector
LOCAL
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:H/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
25.6%
Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/.
Vendor | Product | Version | CPE |
---|---|---|---|
redhat | enterprise_virtualization_manager | * | cpe:2.3:o:redhat:enterprise_virtualization_manager:*:*:*:*:*:*:*:* |
redhat | enterprise_virtualization_manager | 2.1 | cpe:2.3:o:redhat:enterprise_virtualization_manager:2.1:*:*:*:*:*:*:* |
redhat | enterprise_virtualization_manager | 2.2 | cpe:2.3:o:redhat:enterprise_virtualization_manager:2.2:*:*:*:*:*:*:* |
redhat | enterprise_virtualization_manager | 2.2.3 | cpe:2.3:o:redhat:enterprise_virtualization_manager:2.2.3:*:*:*:*:*:*:* |