CVE-2016-5402: Red Hat Cloudforms

High severity, CVSS 8.8. EPSS: 5.9% chance of exploitation in the next 30 days.

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

Affected products

  • Red Hat Cloudforms: version 4.1 only
  • Red Hat Cloudforms Management Engine: version 5.6 only

Published 2018-10-31. Last modified 2026-06-17.