SB2016082605 - Improper access control in CloudForms



SB2016082605 - Improper access control in CloudForms

Published: August 26, 2016 Updated: August 9, 2020

Security Bulletin ID SB2016082605
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2016-5383)

The vulnerability allows a remote authenticated user to execute arbitrary code.

The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."


Remediation

Install update from vendor's website.