Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12675
HistoryJan 15, 2019 - 9:20 a.m.

Privilege Escalation

2019-01-1509:20:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.001 Low

EPSS

Percentile

44.9%

cfme is vulnerable to privilege escalation attacks. The vulnerability exists as CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.

References

0.001 Low

EPSS

Percentile

44.9%