CVE-2013-0168

The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:enterprise_virtualization_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:2.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:2.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:46

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2013-0211.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2013-0211.html - Vendor Advisory
References () http://www.securityfocus.com/bid/57750 - () http://www.securityfocus.com/bid/57750 -
References () http://www.securitytracker.com/id/1028076 - () http://www.securitytracker.com/id/1028076 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=893355 - () https://bugzilla.redhat.com/show_bug.cgi?id=893355 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/81834 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/81834 -

Information

Published : 2013-03-12 23:55

Updated : 2024-11-21 01:46


NVD link : CVE-2013-0168

Mitre link : CVE-2013-0168

CVE.ORG link : CVE-2013-0168


JSON object : View

Products Affected

redhat

  • enterprise_virtualization_manager
CWE
CWE-264

Permissions, Privileges, and Access Controls