CVE-2014-0087

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
11/01/2018
Last modified:
13/02/2023

Description

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:* 5.3 (excluding)