2.1 CVE-2012-5509
Exploit Ransomware Risk
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.
https://nvd.nist.gov/vuln/detail/CVE-2012-5509
Categories
CWE-264
References
CPE
cpe | start | end |
---|---|---|
Configuration 1 | ||
cpe:2.3:a:redhat:cloudforms_cloud_engine:*:*:*:*:*:*:*:* | <= 1.1 | |
cpe:2.3:a:redhat:cloudforms_cloud_engine:1.0:*:*:*:*:*:*:* |
REMEDIATION
EXPLOITS
Exploit-db.com
id | description | date | |
---|---|---|---|
No known exploits |
Other (github, ...)
Url |
---|
https://bugzilla.redhat.com/show_bug.cgi?id=875294 |
CAPEC
Common Attack Pattern Enumerations and Classifications
id | description | severity |
---|---|---|
No entry |
MITRE
Sherlock® flash
Take a picture of your computer network in a few clicks !
The Sherlock® flash audit solution allows you to perform an audit to strengthen the security of your IT assets. Vulnerability analysis of your physical and virtual equipment. Patch planning by priority level and time available. Detailed and intuitive reporting.
