RHEL 7 : CFME 5.7.1 es update (Moderate) (RHSA-2017:0320)

medium Nessus Plugin ID 233184

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2017:0320 advisory.

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

This update fixes various bugs and adds several enhancements. Documentation for these changes is available in the Release Notes linked to in the References section.

Security Fix(es):

* A logic error in valid_role() in CloudForms role validation could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges. (CVE-2017-2632)

This issue was discovered by Matou Moj (Red Hat).

All CFME users are advised to upgrade to these updated packages, which correct these issues and add these enhancements.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected cfme, cfme-appliance and / or cfme-gemset packages.

See Also

https://access.redhat.com/security/updates/classification/#moderate

https://bugzilla.redhat.com/show_bug.cgi?id=1382768

https://bugzilla.redhat.com/show_bug.cgi?id=1390729

https://bugzilla.redhat.com/show_bug.cgi?id=1390731

https://bugzilla.redhat.com/show_bug.cgi?id=1391748

https://bugzilla.redhat.com/show_bug.cgi?id=1391750

https://bugzilla.redhat.com/show_bug.cgi?id=1391757

https://bugzilla.redhat.com/show_bug.cgi?id=1394331

https://bugzilla.redhat.com/show_bug.cgi?id=1394339

https://bugzilla.redhat.com/show_bug.cgi?id=1394341

https://bugzilla.redhat.com/show_bug.cgi?id=1394844

https://bugzilla.redhat.com/show_bug.cgi?id=1395304

https://bugzilla.redhat.com/show_bug.cgi?id=1395839

https://bugzilla.redhat.com/show_bug.cgi?id=1395840

https://bugzilla.redhat.com/show_bug.cgi?id=1395857

https://bugzilla.redhat.com/show_bug.cgi?id=1395898

https://bugzilla.redhat.com/show_bug.cgi?id=1396222

https://bugzilla.redhat.com/show_bug.cgi?id=1396238

https://bugzilla.redhat.com/show_bug.cgi?id=1396239

https://bugzilla.redhat.com/show_bug.cgi?id=1396240

https://bugzilla.redhat.com/show_bug.cgi?id=1396241

https://bugzilla.redhat.com/show_bug.cgi?id=1396243

https://bugzilla.redhat.com/show_bug.cgi?id=1396575

https://bugzilla.redhat.com/show_bug.cgi?id=1396576

https://bugzilla.redhat.com/show_bug.cgi?id=1396577

https://bugzilla.redhat.com/show_bug.cgi?id=1396580

https://bugzilla.redhat.com/show_bug.cgi?id=1397151

https://bugzilla.redhat.com/show_bug.cgi?id=1397154

https://bugzilla.redhat.com/show_bug.cgi?id=1397157

https://bugzilla.redhat.com/show_bug.cgi?id=1397158

https://bugzilla.redhat.com/show_bug.cgi?id=1397159

https://bugzilla.redhat.com/show_bug.cgi?id=1397248

https://bugzilla.redhat.com/show_bug.cgi?id=1397416

https://bugzilla.redhat.com/show_bug.cgi?id=1397509

https://bugzilla.redhat.com/show_bug.cgi?id=1397532

https://bugzilla.redhat.com/show_bug.cgi?id=1397874

https://bugzilla.redhat.com/show_bug.cgi?id=1399207

https://bugzilla.redhat.com/show_bug.cgi?id=1399208

https://bugzilla.redhat.com/show_bug.cgi?id=1399209

https://bugzilla.redhat.com/show_bug.cgi?id=1399211

https://bugzilla.redhat.com/show_bug.cgi?id=1399214

https://bugzilla.redhat.com/show_bug.cgi?id=1399216

https://bugzilla.redhat.com/show_bug.cgi?id=1399221

https://bugzilla.redhat.com/show_bug.cgi?id=1399669

https://bugzilla.redhat.com/show_bug.cgi?id=1399677

https://bugzilla.redhat.com/show_bug.cgi?id=1399679

https://bugzilla.redhat.com/show_bug.cgi?id=1400202

https://bugzilla.redhat.com/show_bug.cgi?id=1400204

https://bugzilla.redhat.com/show_bug.cgi?id=1400212

https://bugzilla.redhat.com/show_bug.cgi?id=1400303

https://bugzilla.redhat.com/show_bug.cgi?id=1400616

https://bugzilla.redhat.com/show_bug.cgi?id=1400704

https://bugzilla.redhat.com/show_bug.cgi?id=1401017

https://bugzilla.redhat.com/show_bug.cgi?id=1401018

https://bugzilla.redhat.com/show_bug.cgi?id=1401030

https://bugzilla.redhat.com/show_bug.cgi?id=1401044

https://bugzilla.redhat.com/show_bug.cgi?id=1401103

https://bugzilla.redhat.com/show_bug.cgi?id=1401935

https://bugzilla.redhat.com/show_bug.cgi?id=1401956

https://bugzilla.redhat.com/show_bug.cgi?id=1401957

https://bugzilla.redhat.com/show_bug.cgi?id=1402118

https://bugzilla.redhat.com/show_bug.cgi?id=1402138

https://bugzilla.redhat.com/show_bug.cgi?id=1402139

https://bugzilla.redhat.com/show_bug.cgi?id=1402162

https://bugzilla.redhat.com/show_bug.cgi?id=1402524

https://bugzilla.redhat.com/show_bug.cgi?id=1402526

https://bugzilla.redhat.com/show_bug.cgi?id=1402527

https://bugzilla.redhat.com/show_bug.cgi?id=1402528

https://bugzilla.redhat.com/show_bug.cgi?id=1402529

https://bugzilla.redhat.com/show_bug.cgi?id=1403011

https://bugzilla.redhat.com/show_bug.cgi?id=1403019

https://bugzilla.redhat.com/show_bug.cgi?id=1403981

https://bugzilla.redhat.com/show_bug.cgi?id=1403983

https://bugzilla.redhat.com/show_bug.cgi?id=1404316

https://bugzilla.redhat.com/show_bug.cgi?id=1404365

https://bugzilla.redhat.com/show_bug.cgi?id=1404427

https://bugzilla.redhat.com/show_bug.cgi?id=1404431

https://bugzilla.redhat.com/show_bug.cgi?id=1404447

https://bugzilla.redhat.com/show_bug.cgi?id=1404454

https://bugzilla.redhat.com/show_bug.cgi?id=1404526

https://bugzilla.redhat.com/show_bug.cgi?id=1404669

https://bugzilla.redhat.com/show_bug.cgi?id=1404746

https://bugzilla.redhat.com/show_bug.cgi?id=1404825

https://bugzilla.redhat.com/show_bug.cgi?id=1404827

https://bugzilla.redhat.com/show_bug.cgi?id=1405193

https://bugzilla.redhat.com/show_bug.cgi?id=1405197

https://bugzilla.redhat.com/show_bug.cgi?id=1405200

https://bugzilla.redhat.com/show_bug.cgi?id=1405201

https://bugzilla.redhat.com/show_bug.cgi?id=1405640

https://bugzilla.redhat.com/show_bug.cgi?id=1405641

https://bugzilla.redhat.com/show_bug.cgi?id=1406160

https://bugzilla.redhat.com/show_bug.cgi?id=1406161

https://bugzilla.redhat.com/show_bug.cgi?id=1406163

https://bugzilla.redhat.com/show_bug.cgi?id=1406167

https://bugzilla.redhat.com/show_bug.cgi?id=1406434

https://bugzilla.redhat.com/show_bug.cgi?id=1406798

https://bugzilla.redhat.com/show_bug.cgi?id=1408278

https://bugzilla.redhat.com/show_bug.cgi?id=1410516

https://bugzilla.redhat.com/show_bug.cgi?id=1410535

https://bugzilla.redhat.com/show_bug.cgi?id=1410587

https://bugzilla.redhat.com/show_bug.cgi?id=1410588

https://bugzilla.redhat.com/show_bug.cgi?id=1410791

https://bugzilla.redhat.com/show_bug.cgi?id=1410817

https://bugzilla.redhat.com/show_bug.cgi?id=1410818

https://bugzilla.redhat.com/show_bug.cgi?id=1410819

https://bugzilla.redhat.com/show_bug.cgi?id=1410828

https://bugzilla.redhat.com/show_bug.cgi?id=1410831

https://bugzilla.redhat.com/show_bug.cgi?id=1410844

https://bugzilla.redhat.com/show_bug.cgi?id=1410845

https://bugzilla.redhat.com/show_bug.cgi?id=1410846

https://bugzilla.redhat.com/show_bug.cgi?id=1410851

https://bugzilla.redhat.com/show_bug.cgi?id=1410927

https://bugzilla.redhat.com/show_bug.cgi?id=1411350

https://bugzilla.redhat.com/show_bug.cgi?id=1411351

https://bugzilla.redhat.com/show_bug.cgi?id=1411353

https://bugzilla.redhat.com/show_bug.cgi?id=1411357

https://bugzilla.redhat.com/show_bug.cgi?id=1411358

https://bugzilla.redhat.com/show_bug.cgi?id=1411359

https://bugzilla.redhat.com/show_bug.cgi?id=1411362

https://bugzilla.redhat.com/show_bug.cgi?id=1411364

https://bugzilla.redhat.com/show_bug.cgi?id=1411368

https://bugzilla.redhat.com/show_bug.cgi?id=1411369

https://bugzilla.redhat.com/show_bug.cgi?id=1411370

https://bugzilla.redhat.com/show_bug.cgi?id=1411372

https://bugzilla.redhat.com/show_bug.cgi?id=1411373

https://bugzilla.redhat.com/show_bug.cgi?id=1411433

https://bugzilla.redhat.com/show_bug.cgi?id=1411459

https://bugzilla.redhat.com/show_bug.cgi?id=1411461

https://bugzilla.redhat.com/show_bug.cgi?id=1411463

https://bugzilla.redhat.com/show_bug.cgi?id=1411466

https://bugzilla.redhat.com/show_bug.cgi?id=1411471

https://bugzilla.redhat.com/show_bug.cgi?id=1411473

https://bugzilla.redhat.com/show_bug.cgi?id=1411478

https://bugzilla.redhat.com/show_bug.cgi?id=1411507

https://bugzilla.redhat.com/show_bug.cgi?id=1411509

https://bugzilla.redhat.com/show_bug.cgi?id=1411511

https://bugzilla.redhat.com/show_bug.cgi?id=1411514

https://bugzilla.redhat.com/show_bug.cgi?id=1411516

https://bugzilla.redhat.com/show_bug.cgi?id=1411517

https://bugzilla.redhat.com/show_bug.cgi?id=1411518

https://bugzilla.redhat.com/show_bug.cgi?id=1411519

https://bugzilla.redhat.com/show_bug.cgi?id=1411791

https://bugzilla.redhat.com/show_bug.cgi?id=1411793

https://bugzilla.redhat.com/show_bug.cgi?id=1411797

https://bugzilla.redhat.com/show_bug.cgi?id=1411878

https://bugzilla.redhat.com/show_bug.cgi?id=1411880

https://bugzilla.redhat.com/show_bug.cgi?id=1411881

https://bugzilla.redhat.com/show_bug.cgi?id=1411882

https://bugzilla.redhat.com/show_bug.cgi?id=1411885

https://bugzilla.redhat.com/show_bug.cgi?id=1411941

https://bugzilla.redhat.com/show_bug.cgi?id=1411973

https://bugzilla.redhat.com/show_bug.cgi?id=1411975

https://bugzilla.redhat.com/show_bug.cgi?id=1411982

https://bugzilla.redhat.com/show_bug.cgi?id=1412206

https://bugzilla.redhat.com/show_bug.cgi?id=1412221

https://bugzilla.redhat.com/show_bug.cgi?id=1412279

https://bugzilla.redhat.com/show_bug.cgi?id=1412280

https://bugzilla.redhat.com/show_bug.cgi?id=1412283

https://bugzilla.redhat.com/show_bug.cgi?id=1412284

https://bugzilla.redhat.com/show_bug.cgi?id=1412285

https://bugzilla.redhat.com/show_bug.cgi?id=1412286

https://bugzilla.redhat.com/show_bug.cgi?id=1412287

https://bugzilla.redhat.com/show_bug.cgi?id=1412288

https://bugzilla.redhat.com/show_bug.cgi?id=1412289

https://bugzilla.redhat.com/show_bug.cgi?id=1412290

https://bugzilla.redhat.com/show_bug.cgi?id=1412291

https://bugzilla.redhat.com/show_bug.cgi?id=1412293

https://bugzilla.redhat.com/show_bug.cgi?id=1412312

https://bugzilla.redhat.com/show_bug.cgi?id=1412314

https://bugzilla.redhat.com/show_bug.cgi?id=1412315

https://bugzilla.redhat.com/show_bug.cgi?id=1412316

https://bugzilla.redhat.com/show_bug.cgi?id=1412383

https://bugzilla.redhat.com/show_bug.cgi?id=1412396

https://bugzilla.redhat.com/show_bug.cgi?id=1412682

https://bugzilla.redhat.com/show_bug.cgi?id=1412738

https://bugzilla.redhat.com/show_bug.cgi?id=1412740

https://bugzilla.redhat.com/show_bug.cgi?id=1412825

https://bugzilla.redhat.com/show_bug.cgi?id=1413086

https://bugzilla.redhat.com/show_bug.cgi?id=1413103

https://bugzilla.redhat.com/show_bug.cgi?id=1413113

https://bugzilla.redhat.com/show_bug.cgi?id=1413119

https://bugzilla.redhat.com/show_bug.cgi?id=1413123

https://bugzilla.redhat.com/show_bug.cgi?id=1413154

https://bugzilla.redhat.com/show_bug.cgi?id=1413167

https://bugzilla.redhat.com/show_bug.cgi?id=1413205

https://bugzilla.redhat.com/show_bug.cgi?id=1413207

https://bugzilla.redhat.com/show_bug.cgi?id=1413210

https://bugzilla.redhat.com/show_bug.cgi?id=1413212

https://bugzilla.redhat.com/show_bug.cgi?id=1413621

https://bugzilla.redhat.com/show_bug.cgi?id=1413677

https://bugzilla.redhat.com/show_bug.cgi?id=1413695

https://bugzilla.redhat.com/show_bug.cgi?id=1413769

https://bugzilla.redhat.com/show_bug.cgi?id=1414012

https://bugzilla.redhat.com/show_bug.cgi?id=1414013

https://bugzilla.redhat.com/show_bug.cgi?id=1414014

https://bugzilla.redhat.com/show_bug.cgi?id=1414015

https://bugzilla.redhat.com/show_bug.cgi?id=1414550

https://bugzilla.redhat.com/show_bug.cgi?id=1414583

https://bugzilla.redhat.com/show_bug.cgi?id=1414848

https://bugzilla.redhat.com/show_bug.cgi?id=1414870

https://bugzilla.redhat.com/show_bug.cgi?id=1414872

https://bugzilla.redhat.com/show_bug.cgi?id=1414876

https://bugzilla.redhat.com/show_bug.cgi?id=1414882

https://bugzilla.redhat.com/show_bug.cgi?id=1414884

https://bugzilla.redhat.com/show_bug.cgi?id=1414885

https://bugzilla.redhat.com/show_bug.cgi?id=1414886

https://bugzilla.redhat.com/show_bug.cgi?id=1414887

https://bugzilla.redhat.com/show_bug.cgi?id=1414888

https://bugzilla.redhat.com/show_bug.cgi?id=1414889

https://bugzilla.redhat.com/show_bug.cgi?id=1414891

https://bugzilla.redhat.com/show_bug.cgi?id=1415217

https://bugzilla.redhat.com/show_bug.cgi?id=1415247

https://bugzilla.redhat.com/show_bug.cgi?id=1415248

https://bugzilla.redhat.com/show_bug.cgi?id=1415332

https://bugzilla.redhat.com/show_bug.cgi?id=1415333

https://bugzilla.redhat.com/show_bug.cgi?id=1415754

https://bugzilla.redhat.com/show_bug.cgi?id=1415755

https://bugzilla.redhat.com/show_bug.cgi?id=1415756

https://bugzilla.redhat.com/show_bug.cgi?id=1416001

https://bugzilla.redhat.com/show_bug.cgi?id=1416077

https://bugzilla.redhat.com/show_bug.cgi?id=1416093

https://bugzilla.redhat.com/show_bug.cgi?id=1416821

https://bugzilla.redhat.com/show_bug.cgi?id=1416826

https://bugzilla.redhat.com/show_bug.cgi?id=1417197

https://bugzilla.redhat.com/show_bug.cgi?id=1417974

https://bugzilla.redhat.com/show_bug.cgi?id=1418400

https://bugzilla.redhat.com/show_bug.cgi?id=1418749

https://bugzilla.redhat.com/show_bug.cgi?id=1418846

https://bugzilla.redhat.com/show_bug.cgi?id=1419186

https://bugzilla.redhat.com/show_bug.cgi?id=1419680

https://bugzilla.redhat.com/show_bug.cgi?id=1419738

https://bugzilla.redhat.com/show_bug.cgi?id=1420555

https://bugzilla.redhat.com/show_bug.cgi?id=1420888

https://bugzilla.redhat.com/show_bug.cgi?id=1420916

https://bugzilla.redhat.com/show_bug.cgi?id=1420917

https://bugzilla.redhat.com/show_bug.cgi?id=1422178

https://bugzilla.redhat.com/show_bug.cgi?id=1422241

https://bugzilla.redhat.com/show_bug.cgi?id=1423031

https://bugzilla.redhat.com/show_bug.cgi?id=1423033

https://bugzilla.redhat.com/show_bug.cgi?id=1424260

https://bugzilla.redhat.com/show_bug.cgi?id=1424275

https://bugzilla.redhat.com/show_bug.cgi?id=1424977

http://www.nessus.org/u?be1960af

https://access.redhat.com/errata/RHSA-2017:0320

Plugin Details

Severity: Medium

ID: 233184

File Name: redhat-RHSA-2017-0320.nasl

Version: 1.1

Type: local

Agent: unix

Published: 3/21/2025

Updated: 3/21/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2013-4492

CVSS v3

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2017-2632

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:cfme-appliance, p-cpe:/a:redhat:enterprise_linux:cfme-gemset, p-cpe:/a:redhat:enterprise_linux:cfme, cpe:/o:redhat:enterprise_linux:7

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 2/27/2017

Vulnerability Publication Date: 12/3/2013

Reference Information

CVE: CVE-2013-4492, CVE-2017-2632

CWE: 285, 79

RHSA: 2017:0320