← Back to CVE List

CVE-2017-2664

Published: 2018-07-26T14:29Z
Last Modified: 2024-11-21T03:23Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt