PT-2020-2046 · Vmware · Vmware Vrealize Log Insight
Published
2020-04-15
·
Updated
2021-07-21
·
CVE-2020-3954
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
VMware vRealize Log Insight versions prior to 8.1.0
Description
The issue is related to insufficient input validation, which can be exploited by a remote attacker to redirect users to a malicious site. This is due to an Open Redirect vulnerability.
Recommendations
For versions prior to 8.1.0, update to version 8.1.0 or later to resolve the issue.
Fix
Open Redirect
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware Vrealize Log Insight