CVE-2018-1000134
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2018-1000134 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
Red Hat Enterprise Virtualization does not use the UnboundID SDK in synchronous mode, and hence does not expose this vulnerability in its default configuration.
CVSS v3 metrics
| CVSS3 Base Score | 7 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Attack Vector | Local |
| Attack Complexity | High |
| Privileges Required | None |
| User Interaction | Required |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity Impact | High |
| Availability Impact | High |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Virtualization 4 (unboundid-ldapsdk) | RHSA-2018:1713 | 2018-05-24 |
External References
CVE description copyright © 2017, The MITRE Corporation
