VDB
CVE-2016-5402
CVE-2016-5402
PUBLISHED
CVSS 8.800000190734863 HIGH
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.
EPSS 5.93% · 92.5th percentile
Risk Scores
CVSS 3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
5.93%
92.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | cloudforms_management_engine | 5.6 |
| [UNKNOWN] | cfme | n/a |
| redhat | cloudforms | 4.1 |
Timeline
- Oct 31, 2018 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- RHSA-2016:2839 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-5402 advisory
- https://access.redhat.com/errata/RHSA-2016:2839 url
- https://access.redhat.com/security/cve/CVE-2016-5402 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1357559 url
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-5402 url
- http://www.securityfocus.com/bid/94612 advisory