CVE-2015-0257: Red Hat Enterprise Virtualization Manager

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.

Affected products

  • Red Hat Enterprise Virtualization Manager: up to and including 3.5.0

Published 2015-05-01. Last modified 2026-06-17.