BDU:2022-02032

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

7.8high3.x
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 3.x
7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C

Description

Уязвимость платформы администрирования приложений VMware Workspace ONE Access, платформы виртуализации VMware Cloud Foundation, средства управления виртуальной инфраструктурой VMware vRealize Automation, программного средства управления жизненным циклом приложений vRealize Suite Lifecycle Manager и консоли администрирования VMware Identity Manager (vIDM), связана с ошибками использования стандартных разрешений. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии с помощью специально сформированного HTTP-запроса

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

bdu

Related Vulnerabilities

Exploits

Exploit ID: BDU:2022-02032

Source: bdu_exploit

URL: https://bdu.fstec.ru/vul

Recommendations

Source: bdu

Использование рекомендаций:
https://www.vmware.com/security/advisories/VMSA-2022-0011.html

URL: https://bdu.fstec.ru/vul/2022-02032

Vulnerable Software (8)

Type: Configuration

Vendor: broadcom inc.

Product: vmware aria automation

Operating System: * *

Trait:
{  "version_exact": "7.6"}

Source: bdu

Type: Configuration

Vendor: broadcom inc.

Product: vmware aria suite lifecycle

Operating System: * *

Trait:
{  "version_end_excluding": "KB88099"}

Source: bdu

Type: Configuration

Vendor: broadcom inc.

Product: vmware cloud foundation

Operating System: * *

Trait:
{  "version_end_excluding": "KB88099"}

Source: bdu

Type: Configuration

Vendor: omnissa

Product: omnissa workspace one access

Operating System: * *

Trait:
{  "version_end_including": "3.3.6",  "version_start_including": "3.3.3"}

Source: bdu

Type: Configuration

Vendor: omnissa

Product: omnissa workspace one access connector

Operating System: * *

Trait:
{  "version_exact": "20.10.0.1"}

Source: bdu

Type: Configuration

Vendor: omnissa

Product: omnissa workspace one access connector

Operating System: * *

Trait:
{  "version_exact": "21.08.0.1"}

Source: bdu

Type: Configuration

Vendor: omnissa

Product: omnissa workspace one access connector

Operating System: * *

Trait:
{  "version_exact": "21.08.0.0"}

Source: bdu

Type: Configuration

Vendor: omnissa

Product: omnissa workspace one access connector

Operating System: * *

Trait:
{  "version_exact": "20.10.0.0"}

Source: bdu

End of list