CVE Database
/

CVE-2017-12191

Back to search

CVE-2017-12191

Published: Feb 28, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.

VendorProductVersions

Red Hat, Inc.

CloudForms

affected
Through 5.9

Weaknesses (CWE)

References

RHSA-2018:0374
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now