CVE-2014-3486
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0018 (0.2%)
Percentile: 38.6%
EPSS: 2026-05-06
Affects
redhat:cloudforms_3.0_management_engineTechnical description
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.
Published: 7/7/2014, 2:55:04 PM
Last modified: 5/6/2026, 10:30:45 PM