Vulnerability Description
Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Theforeman | Foreman | <= 1.8.2 |
Related Weaknesses (CWE)
References
- http://projects.theforeman.org/issues/10829Vendor Advisory
- http://theforeman.org/manuals/1.9/index.html#Releasenotesfor1.9
- https://access.redhat.com/errata/RHSA-2015:1591
- https://access.redhat.com/errata/RHSA-2015:1592
- https://bugzilla.redhat.com/show_bug.cgi?id=1232366
- http://projects.theforeman.org/issues/10829Vendor Advisory
- http://theforeman.org/manuals/1.9/index.html#Releasenotesfor1.9
- https://access.redhat.com/errata/RHSA-2015:1591
- https://access.redhat.com/errata/RHSA-2015:1592
- https://bugzilla.redhat.com/show_bug.cgi?id=1232366
FAQ
What is CVE-2015-3235?
CVE-2015-3235 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
How severe is CVE-2015-3235?
CVE-2015-3235 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-3235?
Check the references section above for vendor advisories and patch information. Affected products include: Theforeman Foreman.