cbcvebase.
CVE-2017-4951
published 2018-01-29

CVE-2017-4951: VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An…

high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices.

Affected

6 ranges
VendorProductVersion rangeFixed in
vmwareairwatch>= 9.1 < 9.1.59.1.5
vmwareairwatch>= 9.2 < 9.2.29.2.2
vmwareairwatch_console
vmwareairwatch_console
vmwarevmware_vrealize
vmwarevmware_vsphere