Skip to main content

Vendor/product archive

redhat / cloudforms_management_engine CVEs

Beta · best-effort

42 CVEs tagged to redhat / cloudforms_management_engine3 Critical, 14 High, 21 Medium, 4 Low, 0 Unrated.

CVE-2014-8164

Published Jul 6, 2022

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14324

Published Aug 11, 2020

A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authen…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14296

Published Aug 11, 2020

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems fr…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10780

Published Aug 11, 2020

Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens th…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14894

Published Jun 22, 2020

A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An att…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10177

Published Jun 27, 2019

A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15123

Published Jun 12, 2019

A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2