CVE-2013-2068
critical
CVSS v3
—
CVSS v2
9.4
VIR risk
9.4
Description
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-1206.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | cloudforms_management_engine | 5.1 | |
References
CWEs
CWE-22
Verify integrity in audit chain (admin only). AS-IS.