CVE-2018-6980
published 2018-11-13CVE-2018-6980: VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method…
PriorityP336high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.44%
70.0th percentile
VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative functions which they are not allowed to perform.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vmware_vrealize | — | — |
| vmware | vmware_vrealize_log_insight | — | — |
| vmware | vrealize_log_insight | >= 4.6 < 4.6.2 | 4.6.2 |
| vmware | vrealize_log_insight | >= 4.7 < 4.7.1 | 4.7.1 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vRealize Log Insight updates address an authorization bypass vulnerability
vendor_vmware·2018-11-13·CVSS 7.2
CVE-2018-6980 [HIGH] VMware vRealize Log Insight updates address an authorization bypass vulnerability
VMSA-2018-0028: VMware vRealize Log Insight updates address an authorization bypass vulnerability
VMware vRealize Log Insight updates address an authorization bypass vulnerability 2. Relevant Products VMware vRealize Log Insight (vRLI) 3. Problem Description vRealize Log Insight improper authorization vulnerability VMware vRealize Log Insight contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative functions which they are not allowed to perform. VMware would like to thank Piotr Madej of ING Tech Poland for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2018-6980
GHSA
GHSA-pvc9-qr25-w7jc: VMware vRealize Log Insight (4
ghsa_unreviewed·2022-05-13
CVE-2018-6980 [HIGH] CWE-863 GHSA-pvc9-qr25-w7jc: VMware vRealize Log Insight (4
VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative functions which they are not allowed to perform.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-11-13
Published