CVE-2014-0137
Red Hat CloudForms Management Engine <5.2.3.2 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0469.html
Scores
EPSS
0.0143
EPSS Percentile
70.2%
Details
CWE
CWE-89
Status
published
Products (4)
redhat/cloudforms_3.0_management_engine
5.2
redhat/cloudforms_3.0_management_engine
5.2.1
redhat/cloudforms_3.0_management_engine
5.2.2
redhat/cloudforms_3.0_management_engine
< 5.2.3
Published
May 14, 2014
Tracked Since
Feb 18, 2026