AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-2614

MEDIUM · CVSS 6.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-27 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2017-2614
Severity
MEDIUM
CVSS
6.8
EPSS
0.28%

Original Filing — NVD Description

When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the password on accounts with expired passwords, gaining access to those accounts.