Lucene search

K
cvelistVmwareCVELIST:CVE-2024-22272
HistoryJun 27, 2024 - 8:22 p.m.

CVE-2024-22272

2024-06-2720:22:17
vmware
www.cve.org
4
vmware
cloud director
privilege management
vulnerability
denial of service

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

9.1%

VMware Cloud Director contains an Improper Privilege Management vulnerability.

An authenticated tenant administrator for a
given organization within VMware Cloud Director may be able to
accidentally disable their organization leading to a Denial of Service
for active sessions within their own organization’s scope.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "VMware Cloud Director",
    "vendor": "N/A",
    "versions": [
      {
        "status": "affected",
        "version": "VMware Cloud Director 10.5.x, VMware Cloud Director 10.4.x"
      }
    ]
  }
]

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

9.1%

Related for CVELIST:CVE-2024-22272