CVE-2016-7047: Red Hat Cloudforms

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.

Affected products

  • Red Hat Cloudforms: version 4.2 only; version 4.5 only
  • Red Hat Cloudforms Management Engine: from 5.6, before 5.6.3.0 (fixed in 5.6.3.0); from 5.7, before 5.7.3.1 (fixed in 5.7.3.1); from 5.8, before 5.8.1.2 (fixed in 5.8.1.2)

Published 2018-09-11. Last modified 2026-06-17.