CVE-2017-7497 MEDIUM

CVE-2017-7497

Vendor [Unknown]
Product CFME
Weakness CWE-284
Published July 27, 2018
Last update August 5, 2024

CVSS base score

4.1/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.

Key dates

02Disclosure timeline

July 27, 2018 CVE published
August 5, 2024 Record updated