Lucene search

K
cveVmwareCVE-2016-7462
HistoryDec 29, 2016 - 9:59 a.m.

CVE-2016-7462

2016-12-2909:59:00
CWE-264
CWE-749
vmware
web.nvd.nist.gov
38
cve-2016-7462
vmware
vrops
vrealize operations
rest api
security vulnerability
deserialization
remote authenticated users
file manipulation

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:P/A:C

CVSS3

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

64.4%

The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.

Affected configurations

Nvd
Node
vmwarevrealize_operationsMatch6.0.0
OR
vmwarevrealize_operationsMatch6.1.0
OR
vmwarevrealize_operationsMatch6.2.0a
OR
vmwarevrealize_operationsMatch6.2.1
OR
vmwarevrealize_operationsMatch6.3.0
VendorProductVersionCPE
vmwarevrealize_operations6.0.0cpe:2.3:a:vmware:vrealize_operations:6.0.0:*:*:*:*:*:*:*
vmwarevrealize_operations6.1.0cpe:2.3:a:vmware:vrealize_operations:6.1.0:*:*:*:*:*:*:*
vmwarevrealize_operations6.2.0acpe:2.3:a:vmware:vrealize_operations:6.2.0a:*:*:*:*:*:*:*
vmwarevrealize_operations6.2.1cpe:2.3:a:vmware:vrealize_operations:6.2.1:*:*:*:*:*:*:*
vmwarevrealize_operations6.3.0cpe:2.3:a:vmware:vrealize_operations:6.3.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:P/A:C

CVSS3

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

AI Score

7.9

Confidence

High

EPSS

0.002

Percentile

64.4%