CVE-2014-3642

medium
Published 2014-10-06 · Modified 2026-05-06
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-1317.html

Application impact

VendorProductVersionsFixed
redhat redhatcloudforms_3.0.1_management_engine5.2.1
redhat redhatcloudforms_3.0.2_management_engine5.2.2
redhat redhatcloudforms_3.0.3_management_engine5.2.3
redhat redhatcloudforms_3.0.4_management_engine5.2.4
redhat redhatcloudforms_3.0.5_management_engine{"endIncluding":"5.2.5"}
redhat redhatcloudforms_3.0_management_engine5.2

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.