It was found that the ovirt-engine-reports setup script would log the reports database password in plaintext to a world-readable file. An attacker with a local user account on the RHEV-M server could use this flaw to access, read and modify the reports database.