PT-2016-6370 · Vmware · Vrealize Automation+1

Publicado

2016-12-29

·

Atualizado

2022-04-08

·

CVE-2016-5334

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Identity Manager versions prior to 2.7.1 vRealize Automation versions prior to 7.2.0
Description The issue allows remote attackers to read sensitive files, specifically /SAAS/WEB-INF and /SAAS/META-INF files, via unspecified vectors.
Recommendations For VMware Identity Manager versions prior to 2.7.1, update to version 2.7.1 or later. For vRealize Automation versions prior to 7.2.0, update to version 7.2.0 or later.

Correção

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-5334

Produtos afetados

Vmware Identity Manager
Vrealize Automation