Red Hat Enterprise Virtualization (RHEV) 3.4

CPE Details

Red Hat Enterprise Virtualization (RHEV) 3.4
3.4
2014-07-11
13h24 +00:00
2014-07-17
15h21 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:enterprise_virtualization:3.4:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

enterprise_virtualization

Version

3.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2015-5201 2020-02-25 19h16 +00:00 VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors.
7.5
High
CVE-2016-6310 2017-08-22 16h00 +00:00 oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.
5.5
Medium
CVE-2014-3561 2014-12-05 15h00 +00:00 The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.
2.1
CVE-2014-3559 2014-08-06 17h00 +00:00 The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage volume.
3.5
CVE-2014-3485 2014-07-11 12h00 +00:00 The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.
4