← All CVEs

CVE-2013-2050

high · 7.5

SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.

7.5
CVSS
15.7%
EPSS (exploit prob.)
97th
EPSS percentile
2014-01-11
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
redhatcloudforms_management_engine5.1
redhatmanageiq_enterprise_virtualization_manager<= 5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-2050