Show plain JSON{"acknowledgement": "This issue was discovered by Simon Lukasik (Red Hat).", "affected_release": [{"advisory": "RHSA-2017:1601", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.7::el7", "package": "cfme-0:5.7.3.2-1.el7cf", "product_name": "CloudForms Management Engine 5.7", "release_date": "2017-06-28T00:00:00Z"}, {"advisory": "RHSA-2017:1601", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.7::el7", "package": "cfme-appliance-0:5.7.3.2-1.el7cf", "product_name": "CloudForms Management Engine 5.7", "release_date": "2017-06-28T00:00:00Z"}, {"advisory": "RHSA-2017:1601", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.7::el7", "package": "cfme-gemset-0:5.7.3.2-1.el7cf", "product_name": "CloudForms Management Engine 5.7", "release_date": "2017-06-28T00:00:00Z"}, {"advisory": "RHSA-2017:1601", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.7::el7", "package": "rh-ruby23-rubygem-nokogiri-0:1.7.2-1.el7cf", "product_name": "CloudForms Management Engine 5.7", "release_date": "2017-06-28T00:00:00Z"}, {"advisory": "RHSA-2017:1601", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.7::el7", "package": "rh-ruby23-rubygem-ovirt-engine-sdk4-0:4.1.5-1.el7cf", "product_name": "CloudForms Management Engine 5.7", "release_date": "2017-06-28T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "ansible-0:2.2.1.0-2.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "ansible-tower-0:3.1.2-1.el7at", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "bubblewrap-0:0.1.7-1.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "cfme-0:5.8.0.17-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "cfme-appliance-0:5.8.0.17-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "cfme-gemset-0:5.8.0.17-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "erlang-0:19.0.4-1.el7at", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "freeipmi-0:1.5.1-2.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "google-compute-engine-0:2.0.0-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "google-config-0:2.0.0-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "libtomcrypt-0:1.17-23.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "libtommath-0:0.42.0-4.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "nginx-1:1.10.2-1.el7at", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "postgresql94-0:9.4.11-2PGDG.el7at", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "prince-0:9.0r2-10.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "python-crypto-0:2.6.1-7.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "python-ecdsa-0:0.11-4.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "python-httplib2-0:0.9.1-2.1.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "python-keyczar-0:0.71c-2.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "python-meld3-0:0.6.10-1.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "python-paramiko-0:1.15.2-3.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "python-passlib-0:1.6.5-1.1.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rabbitmq-server-0:3.6.5-1.el7at", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-postgresql95-postgresql-pglogical-0:1.2.1-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-postgresql95-repmgr-0:3.1.3-2.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-bcrypt-0:3.1.10-3.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-eventmachine-0:1.0.7-6.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-ffi-0:1.9.8-4.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-hamlit-0:2.7.2-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-http_parser.rb-0:0.6.0-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-json-0:2.0.2-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-linux_block_device-0:0.2.1-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-memory_buffer-0:0.1.0-2.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-net_app_manageability-0:0.1.0-3.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-nio4r-0:1.2.1-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-nokogiri-0:1.6.8-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-ovirt-engine-sdk4-0:4.1.5-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-pg-0:0.18.2-5.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-pkg-config-0:1.1.7-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-puma-0:3.3.0-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-redhat_access_cfme-0:1.1.0-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-redhat_access_lib-0:0.1.0-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-rugged-0:0.25.0-b10.2.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-thin-0:1.7.0-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-unf_ext-0:0.0.7.1-3.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "rh-ruby23-rubygem-websocket-driver-0:0.6.3-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "smem-0:1.4-1.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "sshpass-0:1.06-1.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "supervisor-0:3.1.3-3.el7", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}, {"advisory": "RHSA-2017:1367", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5.8::el7", "package": "wmi-0:1.3.14-7.el7cf", "product_name": "CloudForms Management Engine 5.8", "release_date": "2017-05-31T00:00:00Z"}], "bugzilla": {"description": "CFME: default certificate used across all installs", "id": "1341308", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1341308"}, "csaw": false, "cvss": {"cvss_base_score": "5.8", "cvss_scoring_vector": "AV:N/AC:M/Au:N/C:P/I:P/A:N", "status": "verified"}, "cvss3": {"cvss3_base_score": "6.1", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "status": "verified"}, "cwe": "CWE-798", "details": ["CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.", "CloudForms includes a default SSL/TLS certificate for the web server. This certificate is replaced at install time. However if an attacker were able to man-in-the-middle an administrator while installing the new certificate, the attacker could get a copy of the uploaded private key allowing for future attacks."], "name": "CVE-2016-4457", "public_date": "2016-05-31T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2016-4457\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-4457"], "threat_severity": "Moderate"}