The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=893355 | |
http://rhn.redhat.com/errata/RHSA-2013-0211.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/81834 | vdb entry |
http://www.securitytracker.com/id/1028076 | vdb entry |
http://www.securityfocus.com/bid/57750 | vdb entry |