Lucene search

K
redhatcveRedhat.comRH:CVE-2017-2614
HistoryFeb 07, 2017 - 12:18 a.m.

CVE-2017-2614

2017-02-0700:18:10
redhat.com
access.redhat.com
12

EPSS

0

Percentile

12.6%

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.

EPSS

0

Percentile

12.6%