CVE-2015-7502: Red Hat Cloudforms

Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.

Affected products

  • Red Hat Cloudforms: version 3.2 only; version 4.0 only
  • Red Hat Cloudforms Management Engine: version 5.4.4 only; version 5.5.0 only

Published 2016-04-11. Last modified 2026-06-17.