CVE-2014-0199: Red Hat Rhevm-Reports

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.

Affected products

  • Red Hat Rhevm-Reports: up to and including 3.3; version 3.0 only; version 3.1 only; version 3.2 only

Published 2014-05-29. Last modified 2026-06-17.