A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.
References
Link Resource
https://access.redhat.com/errata/RHSA-2018:0374 Patch Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1500517 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-02-28T13:00:00Z

Updated: 2018-03-01T10:57:01

Reserved: 2017-08-01T00:00:00


Link: CVE-2017-12191

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-02-28T13:29:00.210

Modified: 2023-02-12T23:28:03.100


Link: CVE-2017-12191

JSON object: View

cve-icon Redhat Information

No data.