Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2017-7497
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.001
EPSS Ranking
33.4%
CVSS Severity
CVSS v3 Score
4.1
CVSS v2 Score
4.0
References
https://access.redhat.com/errata/RHSA-2017:1601
https://access.redhat.com/errata/RHSA-2017:1758
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7497
https://access.redhat.com/errata/RHSA-2017:1601
https://access.redhat.com/errata/RHSA-2017:1758
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7497
Products affected by CVE-2017-7497
Redhat
»
Cloudforms Management Engine
»
Version:
5.7.2
cpe:2.3:a:redhat:cloudforms_management_engine:5.7.2
Redhat
»
Cloudforms Management Engine
»
Version:
5.8.0
cpe:2.3:a:redhat:cloudforms_management_engine:5.8.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved