Lucene search

K
vmwareVMwareVMSA-2020-0007.2
HistoryApr 14, 2020 - 12:00 a.m.

VMware vRealize Log Insight addresses Cross Site Scripting (XSS) and Open Redirect vulnerabilities (CVE-2020-3953, CVE-2020-3954)

2020-04-1400:00:00
www.vmware.com
23

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

33.8%

3a. Cross Site Scripting (XSS) vulnerabilities in vRealize Log Insight due to improper Input validation (CVE-2020-3953)

vRealize Log Insight does not properly validate user input, resulting in XSS vulnerabilities. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.4.

3b. Open Redirect vulnerability in vRealize Log Insight due to improper Input validation (CVE-2020-3954)

vRealize Log Insight does not properly validate user input, resulting in an Open Redirect vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.1.

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

33.8%

Related for VMSA-2020-0007.2