CVE-2014-0137

Red Hat CloudForms Management Engine <5.2.3.2 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0469.html

Scores

EPSS 0.0143
EPSS Percentile 70.2%

Details

CWE
CWE-89
Status published
Products (4)
redhat/cloudforms_3.0_management_engine 5.2
redhat/cloudforms_3.0_management_engine 5.2.1
redhat/cloudforms_3.0_management_engine 5.2.2
redhat/cloudforms_3.0_management_engine < 5.2.3
Published May 14, 2014
Tracked Since Feb 18, 2026