Vulnerability Name: | CVE-2013-4404 (CCN-90126) | ||||||||
Assigned: | 2013-12-17 | ||||||||
Published: | 2013-12-17 | ||||||||
Updated: | 2021-07-15 | ||||||||
Summary: | cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 4.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CONFIRM Type: UNKNOWN http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=995038 Source: MITRE Type: CNA CVE-2013-4404 Source: REDHAT Type: Vendor Advisory RHSA-2013:1851 Source: REDHAT Type: UNKNOWN RHSA-2013:1852 Source: CCN Type: Red Hat Bugzilla Bug 995038 CVE-2013-4404 cumin: missing authorization checks in forms, charts, and csv export widgets Source: XF Type: UNKNOWN cumin-cve20134404-sec-bypass(90126) Source: CCN Type: Cumin Web site Cumin | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |