PT-2020-3046 · Vmware · Vrealize Operations For Horizon Adapter

An Trinh

·

Published

2020-02-19

·

Updated

2021-07-21

·

CVE-2020-3943

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vRealize Operations for Horizon Adapter versions 6.6.x prior to 6.6.1 vRealize Operations for Horizon Adapter versions 6.7.x prior to 6.7.1
Description The issue is related to the insecure configuration of a JMX RMI service in vRealize Operations for Horizon Adapter. An unauthenticated remote attacker with network access to vRealize Operations, where the Horizon Adapter is running, may be able to execute arbitrary code. The vulnerability is also associated with insufficient input validation, which can allow a remote attacker to execute arbitrary code.
Recommendations For versions 6.6.x prior to 6.6.1, update to version 6.6.1 or later. For versions 6.7.x prior to 6.7.1, update to version 6.7.1 or later. As a temporary workaround, consider disabling the JMX RMI service until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03335
CVE-2020-3943

Affected Products

Vrealize Operations For Horizon Adapter