CVE-2013-0168: Red Hat Enterprise Virtualization Manager

Medium severity, CVSS 4.0. EPSS: 1.9% chance of exploitation in the next 30 days.

The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.

Affected products

  • Red Hat Enterprise Virtualization Manager: up to and including 3.1; version 2.1 only; version 2.2 only; version 2.2.3 only; version 3.0 only

Published 2013-03-12. Last modified 2026-06-16.