CVE-2015-1841

Impact:
Low
Public Date:
2015-03-26
Bugzilla:
1206332: CVE-2015-1841 RHEV-M: webadmin automatic logout fails if VM is selected
It was found that the idle timeout in the Red Hat Enterprise Virtualization Manager Web Admin interface failed to log out a session if a VM has been selected in the VM grid view. This could allow a local attacker to access the web interface if it was left unattended.

Find out more about CVE-2015-1841 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 3.7
Base Metrics AV:L/AC:H/Au:N/C:P/I:P/A:P
Access Vector Local
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts (rhev-hypervisor7) RHSA-2015:1713 2015-09-03
RHEV Hypervisor for RHEL-6 RHSA-2015:1713 2015-09-03

Acknowledgements

This issue was discovered by Einav Cohen or Red Hat.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.