Versio.io

CVE-2015-7502

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 18-11-2015 01:00
Last modified: - 18-11-2015 01:00
Total changes: - 9

Description

CVE-2015-7502 CloudForms: insecure password storage in PostgreSQL database

Common Vulnerability Scoring System (CVSS)

AV:L/AC:M/Au:N/C:C/I:N/A:N
Low
Attack complexity
Local
Attack vector
None
Availability
High
Confidentiality
None
Integrity
-
Privileges required
-
Scope
-
User interaction
4.7
Base score
Exploitability score
Impact score
 

Verification logic

OR
AND
product=cfme-0 AND versionEndExcluding=5.4.4.2-1.el6cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=cfme-gemset-0 AND versionEndExcluding=5.4.4.2-1.el6cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=cfme-0 AND versionEndExcluding=5.5.0.13-2.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=cfme-appliance-0 AND versionEndExcluding=5.5.0.13-1.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=cfme-gemset-0 AND versionEndExcluding=5.5.0.13-1.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=prince-0 AND versionEndExcluding=9.0r2-10.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-bcrypt-0 AND versionEndExcluding=3.1.10-3.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-escape_utils-0 AND versionEndExcluding=1.1.0-2.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-eventmachine-0 AND versionEndExcluding=1.0.7-6.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-ffi-0 AND versionEndExcluding=1.9.8-4.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-json-0 AND versionEndExcluding=1.8.2-9.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-linux_block_device-0 AND versionEndExcluding=0.1.0-2.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-memory_buffer-0 AND versionEndExcluding=0.1.0-2.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-net_app_manageability-0 AND versionEndExcluding=0.1.0-3.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-nokogiri-0 AND versionEndExcluding=1.6.6.2-3.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-pg-0 AND versionEndExcluding=0.18.2-2.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-psych-0 AND versionEndExcluding=2.0.13-4.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-puma-0 AND versionEndExcluding=2.13.4-2.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-redhat_access_cfme-0 AND versionEndExcluding=0.0.7-1.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-redhat_access_lib-0 AND versionEndExcluding=0.0.6-1.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-thin-0 AND versionEndExcluding=1.6.3-2.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=rh-ruby22-rubygem-unf_ext-0 AND versionEndExcluding=0.0.7.1-3.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
AND
product=wmi-0 AND versionEndExcluding=1.3.14-6.el7cf
vendor=Red Hat Enterprise Linux AND product=cloudforms_managementengine AND version=5
 

Reference

 


Keywords

REDHAT

 

CVE-2015-7502

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.