The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2014-0559.html | vendor advisory |