CVE-2017-7505
Estado: ModificadaAlta (8.8)—
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.59%
- Percentil entre todas las CVEs puntuadas: 75
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
- CWE-269
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2017-7505",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "Foreman",
"product": "foreman",
"versions": [
{
"status": "affected",
"version": "1.5 and higher"
}
]
}
]
}
],
"published": "2017-05-26T16:29:00.307",
"references": [
{
"url": "http://projects.theforeman.org/issues/19612",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/98607",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/theforeman/foreman/pull/4545",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://projects.theforeman.org/issues/19612",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/98607",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/theforeman/foreman/pull/4545",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords."
},
{
"lang": "es",
"value": "Foreman desde la versión 1.5, es vulnerable a una comprobación de autorización incorrecta debido a que los usuarios con permiso de administración de usuario que están asignados a alguna organización(es) pueden realizar todas las operaciones otorgadas por estos permisos sobre todos los objetos del usuario administrador fuera de su alcance, tal como la edición de cuentas de administrador global incluyendo el cambio de sus contraseñas."
}
],
"lastModified": "2026-06-17T01:24:29.097",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0142030F-4787-49ED-BD28-DCF6B08B2B65"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.5.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B8B4DBA-EDFE-40FD-BB2E-0011F3565EBB"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.5.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DAAE3F92-1D5B-43FF-975E-4AB61D9E03BE"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "095371A7-99D9-4165-A60B-11697E16BCA3"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A494EF29-52AF-4DCD-8C19-EA2E6B674EF1"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.5.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C94BEAD3-0DAB-48CA-90E0-256ACC920A35"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C72AF96B-8209-4724-9239-C9C68EC51FFD"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.6.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8463E6B9-766C-40A4-BD89-EFFEE36DE39C"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.6.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "242CDCE9-951F-4C5A-8FA0-45725D5D8B3C"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E36451D-B29C-4304-8C88-8F5B59BA49B0"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4DB2E8F-139E-448C-A6CD-9AD542B6BCB2"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9FAFD54-8610-46F8-85D8-AD82F8A929FF"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF62B37D-BD94-4F0A-A9AF-A6C2023540E4"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DF6607D8-EE55-46D0-B803-988B0F1F0BFA"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C0AA8EEB-05AB-44EC-B947-73D8C1052AE2"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9CBD2729-EC33-4F56-8D48-AD69CC39C978"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5BE9D11-66DC-4B8D-B9DE-4DAB658934FB"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B22AE5BB-A419-4941-A257-1BDD2A4A3AAE"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6402D30-B166-4B9F-82FC-FDCA58C495E2"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "603FE5FF-A2FC-409E-B620-AA1408B78C04"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "178D4DDE-4750-4771-92AF-1D7F7B061863"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56B0CDE2-E4C4-4C85-85EE-0A7228CBF0B3"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F04B05B-A06C-4DBA-B2DF-9FE0401D8C0C"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "63021136-C5BE-41A0-8609-E7296BFD55AC"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9EDBB357-E0E2-4B94-B7D5-A41CB86BBCE7"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1992798-5AB8-413B-BB0E-345CE55A93CB"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.8.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C3D9A7A-E39F-4C15-AF2E-9787AB1FF5DD"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1825F24-09E5-4AC4-845B-C9D113372B05"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.9.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3DB65EE-A614-4B86-80C3-271192061B6E"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.9.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36C7DDE4-7088-4478-8B95-D77DDFF79569"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.9.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F236DCB-E141-49F0-8C6C-B852EA116318"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BB3CEC2-1DD0-4089-929D-83936465AB93"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.9.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "941656AB-D39F-4E6E-9822-E058CDBA5372"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.9.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59F32734-F208-44F3-AF08-C43CF54ABAEF"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D4222A4-6382-475E-9B40-F5C9DDCE0F21"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "948AE10B-3E2A-45C0-AC96-BF150A58CF29"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D90380B-010E-4751-AEE3-2C4C854D40E4"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64506529-3D8D-461A-A2AC-311FE16C51F3"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA36878F-C8D1-4353-805D-889664CDA234"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33C6D17A-7933-43F6-8C5E-0187B3282A72"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F469D8A8-C09F-471B-AB46-05EB78D23CA1"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.10.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "976E418A-EE2D-45A1-AAA8-FCE6212CAEC3"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4197DE0-AEB1-41CA-9264-22C29CCD7102"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E058208D-14B4-4D86-9B5D-57383FC5D5ED"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "564712BC-DB56-4B47-936B-C0E326EB38B2"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1138BC97-DAB7-40C6-91C3-3E237FFAEBFD"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87836834-0E63-4756-B67D-1C37EC5BCDF4"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4EFF327-302C-41FF-B67B-6685819DC8D1"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C4845E7-AAAC-4FFF-AC30-3E1900149033"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.11.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDEA0EE7-5EC4-4460-B829-D76254D67483"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2D1166A-4EAE-40B2-8F85-1FA23C3949E2"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A29F6C0-4899-4B9D-8851-75798C801E6A"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC50C954-4292-4A6C-969A-A8F3D12BA453"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5E2DF31-62BF-4FFB-90E4-8BB6199888E6"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E4B323B-0D2E-4E0F-A14F-6AE4D3065A32"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4E1534E-60A5-4EC3-A51E-573BB500EC03"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BF6B691-61CA-4443-B696-810D2C3EE18B"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.12.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "486F116B-3F43-4886-9337-0F34306A7B0E"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.13.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B486F7D7-FFF5-4F91-AC33-860B416771D9"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.13.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A88587F5-5341-484B-AF33-455DE0C898B9"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.13.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86E04C79-B153-4AA7-84C2-568121D90252"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.13.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EEC53BC-3EC2-4412-9FF9-AB178F991CFC"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.13.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0EC7F90D-59CB-455B-8BD6-20645FA638B7"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.13.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CD9E872-083C-46F6-9670-1F50A1B6826D"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.13.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03C7E93A-5D51-4EE8-A072-7640E915922B"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.14.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C38E33F5-E8AA-4BD4-A318-3CF2718FCA63"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.14.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F109A88-D58B-451F-8FF2-BB5C69B26820"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.14.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "114B1CA1-C8DE-4912-A671-5082CBFC235C"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.14.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D73A8F01-CCC9-4350-8A72-2DA9FD0661F9"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.14.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51A78F36-82DE-499D-AD82-A25DFC90CDAB"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.14.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C73C5558-A26C-4D85-AFAB-38180B470069"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.14.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D71DC4B-5C4C-48BE-ADC0-A6B578C8DAEE"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.15.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDB73CC6-0667-480C-920D-98BCBA910C36"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.15.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46BFD4D5-A6B9-4BD0-9C42-347E412F86D7"
},
{
"criteria": "cpe:2.3:a:theforeman:foreman:1.15.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69379E8F-50F7-4776-A37E-955B73785CE3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}