Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-69hc-w7p9-9v7x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.

EPSS

Процентиль: 82%
0.01728
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.

CVSS3: 9.8
fstec
почти 6 лет назад

Уязвимость инструмента мониторинга виртуальной инфраструктуры vRealize Operations, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 82%
0.01728
Низкий

Дефекты

CWE-20