CVE-2013-2050
CVSS V2 High 7.5
CVSS V3 None
Description
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.
Overview
- CVE ID
- CVE-2013-2050
- Assigner
- secalert@redhat.com
- Vulnerability Status
- Modified
- Published Version
- 2014-01-11T01:55:02
- Last Modified Date
- 2023-02-13T04:42:44
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:redhat:cloudforms_management_engine:5.1:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:a:redhat:manageiq_enterprise_virtualization_manager:*:*:*:*:*:*:*:* | 1 | OR | 5.0 |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- Access Vector
- NETWORK
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- PARTIAL
- Integrity Impact
- PARTIAL
- Availability Impact
- PARTIAL
- Base Score
- 7.5
- Severity
- HIGH
- Exploitability Score
- 10
- Impact Score
- 6.4
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2013-2050 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2050 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 08:46:46 | Added to TrackCVE | |||
2022-12-01 21:27:57 | 2014-01-11T01:55Z | 2014-01-11T01:55:02 | CVE Published Date | updated |
2022-12-01 21:27:57 | 2017-08-29T01:33:13 | CVE Modified Date | updated | |
2022-12-01 21:27:57 | Modified | Vulnerability Status | updated | |
2023-02-02 19:04:09 | 2023-02-02T18:17:32 | CVE Modified Date | updated | |
2023-02-02 19:04:09 | SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action. | CVE-2013-2050 CloudForms Management Engine 2: miq_policy/explorer SQL injection | Description | updated |
2023-02-02 19:04:15 | References | updated | ||
2023-02-13 05:06:19 | 2023-02-13T04:42:44 | CVE Modified Date | updated | |
2023-02-13 05:06:20 | CVE-2013-2050 CloudForms Management Engine 2: miq_policy/explorer SQL injection | SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action. | Description | updated |