PT-2018-17856 · Vmware · Vrealize Operations

Published

2018-12-18

·

Updated

2019-10-03

·

CVE-2018-6978

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vRealize Operations versions 7.x before 7.0.0.11287810 vRealize Operations versions 6.7.x before 6.7.0.11286837 vRealize Operations versions 6.6.x before 6.6.1.11286876
Description The issue is due to improper permissions of support scripts, allowing a local privilege escalation. An admin user of the vROps application with shell access may exploit this to elevate privileges to root on a vROps machine. It is important to note that the admin user in this context is a non-sudoer and should not be confused with the root user of the vROps machine.
Recommendations For versions 7.x before 7.0.0.11287810, update to version 7.0.0.11287810 or later. For versions 6.7.x before 6.7.0.11286837, update to version 6.7.0.11286837 or later. For versions 6.6.x before 6.6.1.11286876, update to version 6.6.1.11286876 or later.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6978

Affected Products

Vrealize Operations