Vulnerabilities > Vmware > Airwatch

DATE CVE VULNERABILITY TITLE RISK
2018-01-29 CVE-2017-4951 Cross-Site Request Forgery (CSRF) vulnerability in VMWare Airwatch
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog.
network
low complexity
vmware CWE-352
8.8
2017-11-16 CVE-2017-4931 Improper Input Validation vulnerability in VMWare Airwatch
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled device's log files.
local
low complexity
vmware CWE-20
7.8
2017-11-16 CVE-2017-4930 Cross-site Scripting vulnerability in VMWare Airwatch
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page.
network
low complexity
vmware CWE-79
5.4