Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/56825 | vdb entry |
http://rhn.redhat.com/errata/RHSA-2012-1506.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/80546 | vdb entry |
http://www.securitytracker.com/id?1027838 | vdb entry |