CVE-2013-2144: Red Hat Enterprise Virtualization Manager
Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.
Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service (disk space consumption) by cloning a VM from a snapshot.
Affected products
- Red Hat Enterprise Virtualization Manager: up to and including 3.1; version 2.1 only; version 2.2 only; version 2.2.3 only; version 3.0 only
Published 2013-07-03. Last modified 2026-06-16.