CVE-2014-0200
Red Hat Enterprise Virtualization Manager <3.3.3-1 - Info Disclosure
Title source: llmDescription
The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permissions on the datasource configuration file (js-jboss7-ds.xml), which allows local users to obtain sensitive information by reading the file.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/67684
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0558.html
Scores
EPSS
0.0037
EPSS Percentile
29.7%
Details
CWE
CWE-264
Status
published
Products (5)
redhat/rhevm-reports
3.0
redhat/rhevm-reports
3.1
redhat/rhevm-reports
3.2
redhat/rhevm-reports
3.3
redhat/rhevm-reports
< 3.3.3
Published
May 29, 2014
Tracked Since
Feb 18, 2026