CVE-2017-12191
Last modified
CVE-2017-12191 is a vulnerability of currently unknown severity. A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Cloudforms | 4.5 |
References
- https://access.redhat.com/errata/RHSA-2018:0374Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500517Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0374Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500517Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12191?
How severe is CVE-2017-12191?
How do I fix CVE-2017-12191?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-12186xorg-x11-server before 1.19.5 was missing length validation …
- CVE-2017-12187xorg-x11-server before 1.19.5 was missing length validation …
- CVE-2017-12188arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when …7.8
- CVE-2017-12189It was discovered that the jboss init script as used in Red …
- CVE-2017-1219IBM Tivoli Endpoint Manager is vulnerable to a XML External …
- CVE-2017-12190The bio_map_user_iov and bio_unmap_user functions in block/b…
- CVE-2017-12192The keyctl_read_key function in security/keys/keyctl.c in th…
- CVE-2017-12193The assoc_array_insert_into_terminal_node function in lib/as…
- CVE-2017-12194A flaw was found in the way spice-client processed certain m…
- CVE-2017-12195A flaw was found in all Openshift Enterprise versions using …6.5
- CVE-2017-12196undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Fin…4.8
- CVE-2017-12197It was found that libpam4j up to and including 1.8 did not p…
Are you affected by CVE-2017-12191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
