The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to delete arbitrary catalogs via vectors involving guessing the catalog ID.
| Software | From | Fixed in |
|---|---|---|
| redhat / cloudforms_3.0_management_engine | 5.2.1 | 5.2.1.x |
| redhat / cloudforms_3.0_management_engine | - | 5.2.3.x |
| redhat / cloudforms_3.0_management_engine | 5.2.2 | 5.2.2.x |
| redhat / cloudforms_3.0_management_engine | 5.2 | 5.2.x |