VMware vRealize Operations 6.7.0 for Horizon

CPE Details

VMware vRealize Operations 6.7.0 for Horizon
6.7.0
2020-02-28 12:16 +00:00
2020-02-28 12:16 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:vmware:vrealize_operations:6.7.0:*:*:*:*:horizon:*:*

Informations

Vendor

vmware

Product

vrealize_operations

Version

6.7.0

Target Software

horizon

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-3943 2020-02-19 19:04 +00:00 vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.
9.8
CRITICAL
CVE-2020-3944 2020-02-19 19:03 +00:00 vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter authentication.
8.6
HIGH
CVE-2020-3945 2020-02-19 19:03 +00:00 vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information
7.5
HIGH
CVE-2018-6978 2018-12-18 19:00 +00:00 vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root on a vROps machine. Note: the admin user (non-sudoer) should not be confused with root of the vROps machine.
6.7
MEDIUM
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.