The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2016-1967.html | Vendor Advisory |
http://www.securityfocus.com/bid/92694 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1371428 | Issue Tracking Patch Vendor Advisory |
https://gerrit.ovirt.org/#/q/I40c88ad48f8f7c2b8e06802137870b0c198b5129 | Patch |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2016-10-03 18:59
Updated : 2023-02-12 23:24
NVD link : CVE-2016-5432
Mitre link : CVE-2016-5432
CVE.ORG link : CVE-2016-5432
JSON object : View
Products Affected
redhat
- enterprise_linux
- enterprise_virtualization
CWE
CWE-532
Insertion of Sensitive Information into Log File