CVE-2016-7040
high
CVSS v3
8.8
CVSS v2
9.0
VIR risk
8.8
Description
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://rhn.redhat.com/errata/RHSA-2016-1996.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | cloudforms_management_engine | 4.1 | |
References
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.