CVE-2017-2663

high

Description

It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.

References

https://github.com/candlepin/subscription-manager/commit/2aa48ef65

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2663

http://www.securityfocus.com/bid/97015

Details

Source: Mitre, NVD

Published: 2018-07-27

Updated: 2019-10-09

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High