Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12545
HistoryJan 15, 2019 - 9:18 a.m.

Information Disclosure

2019-01-1509:18:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

44.2%

cfme is vulnerable to information disclosure attacks. The vulnerability exists as a flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.

References

0.001 Low

EPSS

Percentile

44.2%

Related for VERACODE:12545