CVE-2013-2144: Red Hat Enterprise Virtualization Manager

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service (disk space consumption) by cloning a VM from a snapshot.

Affected products

  • Red Hat Enterprise Virtualization Manager: up to and including 3.1; version 2.1 only; version 2.2 only; version 2.2.3 only; version 3.0 only

Published 2013-07-03. Last modified 2026-06-16.