Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
No PoCs from references.
- https://github.com/rcvalle/vulnerabilities