PT-2018-2687 · Vmware · Vmware Vrealize Log Insight
Publicado
2018-11-13
·
Atualizado
2019-10-03
·
CVE-2018-6980
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware vRealize Log Insight versions 4.7.x before 4.7.1
VMware vRealize Log Insight versions 4.6.x before 4.6.2
Description
The issue is related to improper authorization in the user registration method. Successful exploitation may allow Admin users with view-only permission to perform certain administrative functions they are not allowed to perform. The vulnerability can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions 4.7.x before 4.7.1, update to version 4.7.1 or later.
For versions 4.6.x before 4.6.2, update to version 4.6.2 or later.
Correção
Improper Authorization
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vmware Vrealize Log Insight