CVE-2016-7462
published 2016-12-29CVE-2016-7462: The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename…
PriorityP351high8.5CVSS 3.0
AVNACLPRLUINSCCNILAH
EPSS
2.04%
79.0th percentile
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
| vmware | vrealize_operations | — | — |
CVSS provenance
nvdv3.08.5HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:S/C:N/I:P/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
vRealize Operations update addresses REST API deserialization vulnerability
vendor_vmware·2016-11-15·CVSS 8.5
CVE-2016-7462 [HIGH] vRealize Operations update addresses REST API deserialization vulnerability
VMSA-2016-0020: vRealize Operations update addresses REST API deserialization vulnerability
a. vRealize Operations REST API deserialization vulnerability vRealize Operations contains a deserialization vulnerability in its REST API implementation. This issue may result in a Denial of Service as it allows for writing of files with arbitrary content and moving existing files into certain folders. The name format of the destination files is predefined and their names cannot be chosen. Overwriting files is not feasible. VMware would like to thank Jacob Baines of Tenable Network Security for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-7462 to this issue. Column 5 of the following table lists the action require
GHSA
GHSA-v9q7-cmc5-22hj: The Suite REST API in VMware vRealize Operations (aka vROps) 6
ghsa_unreviewed·2022-05-17
CVE-2016-7462 [HIGH] GHSA-v9q7-cmc5-22hj: The Suite REST API in VMware vRealize Operations (aka vROps) 6
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/94351http://www.securitytracker.com/id/1037297http://www.vmware.com/security/advisories/VMSA-2016-0020.htmlhttps://www.tenable.com/security/research/tra-2016-34http://www.securityfocus.com/bid/94351http://www.securitytracker.com/id/1037297http://www.vmware.com/security/advisories/VMSA-2016-0020.htmlhttps://www.tenable.com/security/research/tra-2016-34
2016-12-29
Published