CVE-2016-7457
published 2016-12-29CVE-2016-7457: VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via…
PriorityP355critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
3.18%
86.7th percentile
VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.08.0HIGHAV:N/AC:L/Au:S/C:P/I:P/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
vRealize Operations (vROps) updates address privilege escalation vulnerability
vendor_vmware·2016-10-11·CVSS 10.0
CVE-2016-7457 [CRITICAL] vRealize Operations (vROps) updates address privilege escalation vulnerability
VMSA-2016-0016: vRealize Operations (vROps) updates address privilege escalation vulnerability
vROps privilege escalation issue vROps contains a privilege escalation vulnerability. Exploitation of this issue may allow a vROps user who has been assigned a low-privileged role to gain full access over the application. In addition it may be possible to stop and delete Virtual Machines managed by vCenter. VMware would like to thank Edgar Carvalho for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-7457 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/
GHSA
GHSA-xm6j-mv8r-9mhp: VMware vRealize Operations (aka vROps) 6
ghsa_unreviewed·2022-05-17
CVE-2016-7457 [CRITICAL] GHSA-xm6j-mv8r-9mhp: VMware vRealize Operations (aka vROps) 6
VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93499http://www.securitytracker.com/id/1036999http://www.vmware.com/security/advisories/VMSA-2016-0016.htmlhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03707en_ushttp://www.securityfocus.com/bid/93499http://www.securitytracker.com/id/1036999http://www.vmware.com/security/advisories/VMSA-2016-0016.htmlhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03707en_us
2016-12-29
Published