← back
CVE-2017-7497mediumCWE-284

CVE-2017-7497

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.1epss 1.0%
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Affected products
[UNKNOWN] · CFME