Show plain JSON{"acknowledgement": "This issue was discovered by Simon Lukasik (Red Hat).", "affected_release": [{"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "cfme-0:5.6.0.13-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "cfme-appliance-0:5.6.0.13-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "cfme-gemset-0:5.6.0.13-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "prince-0:9.0r2-10.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-postgresql94-postgresql-pglogical-0:1.0.1-3.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-postgresql94-postgresql-pglogical-output-0:1.0.1-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-bcrypt-0:3.1.10-3.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-escape_utils-0:1.1.0-2.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-eventmachine-0:1.0.7-6.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-ffi-0:1.9.8-4.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-hamlit-0:2.0.2-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-http_parser.rb-0:0.6.0-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-json-0:1.8.2-9.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-linux_block_device-0:0.1.0-2.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-memory_buffer-0:0.1.0-2.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-net_app_manageability-0:0.1.0-3.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-nio4r-0:1.2.1-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-nokogiri-0:1.6.6.2-3.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-pg-0:0.18.2-2.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-psych-0:2.0.13-4.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-puma-0:3.3.0-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-redhat_access_cfme-0:1.0.3-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-redhat_access_lib-0:0.0.6-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-rugged-0:0.23.3-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-thin-0:1.6.3-2.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-unf_ext-0:0.0.7.1-3.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "rh-ruby22-rubygem-websocket-driver-0:0.6.3-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "smem-0:1.4-1.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}, {"advisory": "RHBA-2016:1348", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.6::el7", "package": "wmi-0:1.3.14-6.el7cf", "product_name": "CloudForms Management Engine 5.6", "release_date": "2016-06-29T00:00:00Z"}], "bugzilla": {"description": "cfme: Privilege escalation causing arbitrary code execution", "id": "1340763", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1340763"}, "csaw": false, "cvss": {"cvss_base_score": "3.7", "cvss_scoring_vector": "AV:L/AC:H/Au:N/C:P/I:P/A:P", "status": "verified"}, "details": ["ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code."], "name": "CVE-2016-4471", "package_state": [{"cpe": "cpe:/a:cloudforms_managementengine:5.3", "fix_state": "Affected", "package_name": "cfme", "product_name": "CloudForms Management Engine 5.3"}, {"cpe": "cpe:/a:cloudforms_managementengine:5.4", "fix_state": "Affected", "package_name": "cfme", "product_name": "CloudForms Management Engine 5.4"}, {"cpe": "cpe:/a:cloudforms_managementengine:5.5", "fix_state": "Affected", "package_name": "cfme", "product_name": "CloudForms Management Engine 5.5"}], "public_date": "2016-08-12T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-4471\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-4471"], "threat_severity": "Low"}