CVE-2013-2068: Red Hat Cloudforms Management Engine

High severity, CVSS 9.4. EPSS: 58.6% chance of exploitation in the next 30 days.

Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.

Affected products

  • Red Hat Cloudforms Management Engine: version 5.1 only

Published 2013-09-28. Last modified 2026-06-16.