CVE-2017-4951
published 2018-01-29CVE-2017-4951: VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An…
PriorityP336high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.83%
53.6th percentile
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | airwatch | >= 9.1 < 9.1.5 | 9.1.5 |
| vmware | airwatch | >= 9.2 < 9.2.2 | 9.2.2 |
| vmware | airwatch_console | — | — |
| vmware | airwatch_console | — | — |
| vmware | vmware_vrealize | — | — |
| vmware | vmware_vsphere | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-97q6-87j9-jw23: VMware AirWatch Console (9
ghsa_unreviewed·2022-05-14
CVE-2017-4951 [HIGH] CWE-352 GHSA-97q6-87j9-jw23: VMware AirWatch Console (9
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices.
VMware
vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities
vendor_vmware·2018-01-26·CVSS 9.8
CVE-2017-4947 [CRITICAL] vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities
VMSA-2018-0006: vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities
vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities 2. Relevant Products vRealize Automation (vRA) vSphere Integrated Containers (VIC) VMware AirWatch Console (AWC) 3. Problem Description a. vRealize Automation and vSphere Integrated Containers deserialization vulnerability via Xenon vRealize Automation and vSphere Integrated Containers contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-01-29
Published