CVE-2015-3251

MEDIUM

Apache CloudStack <4.5.2 - Info Disclosure

Title source: llm

Description

Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.

Scores

CVSS v3 4.9
EPSS 0.0018
EPSS Percentile 39.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (2)

apache/cloudstack
apache/cloudstack

Timeline

Published Feb 08, 2016
Tracked Since Feb 18, 2026