PT-2020-3048 · Vmware · Vrealize Operations For Horizon Adapter+1
Published
2020-02-19
·
Updated
2021-07-21
·
CVE-2020-3945
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
vRealize Operations for Horizon Adapter versions 6.6.x prior to 6.6.1
vRealize Operations for Horizon Adapter versions 6.7.x prior to 6.7.1
Description
The issue is related to an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker with network access to vRealize Operations, where the Horizon Adapter is running, may obtain sensitive information.
Recommendations
For versions 6.6.x prior to 6.6.1, update to version 6.6.1 or later.
For versions 6.7.x prior to 6.7.1, update to version 6.7.1 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horizon View
Vrealize Operations For Horizon Adapter