Red Hat Bugzilla – Bug 1094229
CVE-2014-0200 ovirt-engine-reports: js-jboss7-ds.xml is world-readable
Last modified: 2015-01-29 04:23:25 EST
It was found that the RHEV-M reports datasource configuration file (js-jboss7-ds.xml) is world-readable. An attacker with a local user account on the RHEV-M server could use this flaw to access, read and modify the reports database.
Acknowledgements: This issue was discovered by Red Hat.
This issue has been addressed in following products: RHEV Manager version 3.3 Via RHSA-2014:0558 https://rhn.redhat.com/errata/RHSA-2014-0558.html