博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
CVE-2014-0199 CVE-2014-0200 CVE-2014-0201 POC
阅读量:2433 次
发布时间:2019-05-10

本文共 1171 字,大约阅读时间需要 3 分钟。

It was found that the ovirt-engine-reports setup script logged the reports

database password in plain text to a world-readable file. An attacker with

a local user account on the Red Hat Enterprise Virtualization Manager

server could use this flaw to access, read, and modify the reports

database. (CVE-2014-0199)


Note: Applying the update provided by this advisory does not modify any

existing log files. It is recommended that you search your existing log

files and remove any occurrences of plain text passwords manually.


It was found that the Red Hat Enterprise Virtualization Manager reports

datasource configuration file (js-jboss7-ds.xml) was world-readable.

An attacker with a local user account on the Red Hat Enterprise

Virtualization Manager server could use this flaw to access, read, and

modify the reports database. (CVE-2014-0200)


It was found that multiple ovirt-engine-reports configuration files were

world-readable. An attacker with a local user account on the Red Hat

Enterprise Virtualization Manager server could use this flaw to access a

variety of potentially sensitive information. (CVE-2014-0201)

https://rhn.redhat.com/errata/RHSA-2014-0558.html

转载地址:http://gummb.baihongyu.com/

你可能感兴趣的文章
Python numpy小练习
查看>>
Linux命令英文解释(按英文字母顺序)
查看>>
秋招面试准备-数据库知识
查看>>
数据分析岗-机器学习相关知识
查看>>
分类模型的效果评估
查看>>
深入理解什么是Java双亲委派模型
查看>>
MySQL优化Limit查询语句
查看>>
轻松入门MySQL主从复制原理
查看>>
SpringCloud全家桶---Zuul网关
查看>>
基于zuul和ribbon的灰度发布方案
查看>>
JVM常用垃圾收集器参数说明
查看>>
MySQL索引基础知识梳理
查看>>
MySQL事务ACID底层实现原理
查看>>
关于MySQL wait_timeout问题记录
查看>>
基础算法面试题---如何用栈实现队列
查看>>
基础算法面试题---如何用队列实现栈(1)
查看>>
基础算法面试题---如何用队列实现栈(2)
查看>>
基础算法面试题---如何数组实现栈和队列
查看>>
API接口安全性设计以及各参数的作用
查看>>
《Netty权威指南 第2版》学习笔记(1)---服务端与客户端开发入门
查看>>