CVE-2014-7813
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors involving calls to the .to_sym rails function and lack of garbage collection of inserted symbols.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=1157872
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | cloudforms_3.0_management_engine | - | |
References
CWEs
CWE-400
Verify integrity in audit chain (admin only). AS-IS.