CVE-2015-3251: Apache Cloudstack
Medium severity, CVSS 4.9. EPSS: 2.5% chance of exploitation in the next 30 days.
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
Affected products
- Apache Cloudstack: version 4.4.4 only; version 4.5.1 only
Published 2016-02-08. Last modified 2026-06-17.