CVE-2016-5335
published 2016-08-31CVE-2016-5335: VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.6th percentile
VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | identity_manager | >= 2.0 < 2.7 | 2.7 |
| vmware | vmware_identity_manager | — | — |
| vmware | vrealize_automation | >= 7.0 < 7.1 | 7.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26wf-vqvv-w3p8: VMware Identity Manager 2
ghsa_unreviewed·2022-05-13
CVE-2016-5335 [HIGH] GHSA-26wf-vqvv-w3p8: VMware Identity Manager 2
VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
VMware
VMware Identity Manager and vRealize Automation updates address multiple security issues
vendor_vmware·2016-08-23·CVSS 7.8
CVE-2016-5335 [HIGH] VMware Identity Manager and vRealize Automation updates address multiple security issues
VMSA-2016-0013: VMware Identity Manager and vRealize Automation updates address multiple security issues
a. VMware Identity Manager local privilege escalation vulnerability VMware Identity Manager and vRealize Automation both contain a vulnerability that may allow for a local privilege escalation. Exploitation of this issue may lead to an attacker with access to a low-privileged account to escalate their privileges to that of root. The Common Vulnerabilities and Exposures project (cve.mitre.org) has reserved the identifier CVE-2016-5335 for this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch*
CVEs: CVE-2016-5335, CVE-20
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-08-31
Published