AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-7851

HIGH · CVSS 7.5 EPSS 1.00%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-10-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2014-7851
Severity
HIGH
CVSS
7.5
EPSS
1.00%

Original NVD Description

oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.