We found results for “”
CVE-2017-4952
Good to know:
Date: May 2, 2018
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may result in information disclosure.
Language: Java
Severity Score
Related Resources (13)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version v1.1.0-CR0-3-release,v1.1.0-CR3_1-release,v1.3.7-CR1_2-release,,v1.4.2-CR4_1-release,v1.5.4-CR6_2-release,v1.5.4-CR7_1-release,v1.5.4_8-release,v1.5.7_7-release
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |