PT-2018-1080 · Vmware · Vmware Vrealize Automation+2

Published

2018-01-26

·

Updated

2024-09-17

·

CVE-2017-4947

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware vRealize Automation versions 7.2 through 7.3 vSphere Integrated Containers versions 1.x before 1.3
Description The issue is caused by a deserialization vulnerability via Xenon, which may allow remote attackers to execute arbitrary code on the appliance by sending specially crafted data to the Xenon service. This vulnerability exists due to the restoration in memory of an untrusted data structure.
Recommendations For VMware vRealize Automation versions 7.2 and 7.3, update to a version that contains a fix for this issue. For vSphere Integrated Containers versions 1.x before 1.3, update to version 1.3 or later. As a temporary workaround, consider restricting access to the Xenon service to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2018-00442
CVE-2017-4947

Affected Products

Vmware Vrealize Automation
Xenon
Vsphere Integrated Containers