CVE-2014-0057: Red Hat Cloudforms

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remote attackers to execute arbitrary methods via unspecified vectors.

Affected products

  • Red Hat Cloudforms: version 3.0 only
  • Red Hat Cloudforms 3.0 Management Engine: version 5.2 only

Published 2014-03-18. Last modified 2026-06-17.