CVE-2016-4471
ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
Read MoreManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
Read MoreThe PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
Read Moreclient/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable.
Read Morepulp.spec in Pulp 2.8.3 allows local users to read generated RSA keys.
Read MoreThe Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the “/etc/pki/pulp/nodes/” directory, which allows local users to gain access to sensitive data.
Read More