Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
This is now public: https://www.ansible.com/security
This issue has been addressed in Ansible Tower release 3.1.6 and 3.2.4, for more information please see https://www.ansible.com/security
Acknowledgments: Name: Graham Mainwaring (Red Hat)
This issue has been addressed in the following products: CloudForms Management Engine 5.9 Via RHSA-2018:1328 https://access.redhat.com/errata/RHSA-2018:1328
This issue has been addressed in the following products: CloudForms Management Engine 5.8 Via RHSA-2018:1972 https://access.redhat.com/errata/RHSA-2018:1972