Show plain JSON{"acknowledgement": "This issue was discovered by Jan Rusnacko (Red Hat Product Security Team).", "affected_release": [{"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "cfme-0:5.2.2.3-1.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-ruby-0:1.9.3.448-40.1.el6", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-actionpack-1:3.2.13-5.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-amq-protocol-0:1.9.2-3.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-bunny-0:1.0.7-1.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-excon-0:0.31.0-1.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-fog-0:1.19.0-1.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-linux_admin-0:0.7.0-1.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-more_core_extensions-0:1.1.2-1.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}, {"advisory": "RHSA-2014:0215", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby193-rubygem-nokogiri-0:1.5.6-3.el6cf", "product_name": "CloudForms Management Engine 5.x", "release_date": "2014-03-11T00:00:00Z"}], "bugzilla": {"description": "CFME: Dangerous send in ServiceController", "id": "1064140", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1064140"}, "csaw": false, "cvss": {"cvss_base_score": "6.5", "cvss_scoring_vector": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "status": "verified"}, "cwe": "CWE-470", "details": ["The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remote attackers to execute arbitrary methods via unspecified vectors."], "name": "CVE-2014-0057", "public_date": "2014-03-11T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2014-0057\nhttps://nvd.nist.gov/vuln/detail/CVE-2014-0057"], "threat_severity": "Important"}