VDB

CVE-2014-3559

CVE-2014-3559 PUBLISHED CVSS 3.5 LOW

The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage volume.

EPSS 1.44% · 71.3th percentile

Risk Scores

CVSS 2.0
3.5
EPSS Score
1.44%
71.3th percentile

Affected Products

VendorProductVersions
n/an/an/a
redhatenterprise_virtualization3.4

Timeline

  • Aug 6, 2014 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›