Vmware Vrealize Operations For Horizon Adapter vulnerabilities
3 known vulnerabilities affecting vmware/vrealize_operations_for_horizon_adapter.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-3943CRITICALCVSS 9.8v6.7.x prior to 6.7.1v6.6.x prior to 6.6.12020-02-19
CVE-2020-3943 [CRITICAL] CVE-2020-3943: vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX R
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.
cvelistv5nvd
CVE-2020-3944HIGHCVSS 8.6v6.7.x prior to 6.7.1v6.6.x prior to 6.6.12020-02-19
CVE-2020-3944 [HIGH] CWE-287 CVE-2020-3944: vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an impro
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter authentication.
cvelistv5nvd
CVE-2020-3945HIGHCVSS 7.5v6.7.x prior to 6.7.1v6.6.x prior to 6.6.12020-02-19
CVE-2020-3945 [HIGH] CVE-2020-3945: vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, m
cvelistv5nvd