Vulnerabilities > Vmware

DATE CVE VULNERABILITY TITLE RISK
2020-02-19 CVE-2020-3945 Unspecified vulnerability in VMWare Vrealize Operations 6.6.0/6.7.0
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View.
network
low complexity
vmware
7.5
2020-02-19 CVE-2020-3944 Improper Authentication vulnerability in VMWare Vrealize Operations 6.6.0/6.7.0
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass.
network
low complexity
vmware CWE-287
8.6
2020-02-19 CVE-2020-3943 Unspecified vulnerability in VMWare Vrealize Operations 6.6.0/6.7.0
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured.
network
low complexity
vmware
critical
9.8
2020-01-17 CVE-2020-5397 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints.
network
low complexity
vmware oracle CWE-352
5.3
2020-01-17 CVE-2020-3940 Improper Certificate Validation vulnerability in VMWare products
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
network
high complexity
vmware CWE-295
5.9
2020-01-17 CVE-2020-5398 Download of Code Without Integrity Check vulnerability in multiple products
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
network
high complexity
vmware oracle netapp CWE-494
7.5
2020-01-15 CVE-2020-3941 Race Condition vulnerability in VMWare Tools
The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in the Virtual Machine where Tools is installed.
local
high complexity
vmware CWE-362
7.0
2020-01-02 CVE-2016-1000027 Deserialization of Untrusted Data vulnerability in VMWare Spring Framework
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data.
network
low complexity
vmware CWE-502
critical
9.8
2019-12-23 CVE-2019-5539 Uncontrolled Search Path Element vulnerability in VMWare Horizon View Agent and Workstation
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint.
local
low complexity
vmware CWE-427
7.8
2019-12-06 CVE-2019-5544 Out-of-bounds Write vulnerability in multiple products
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
network
low complexity
vmware redhat openslp fedoraproject CWE-787
critical
9.8