VMware vCloud Director Cross Site Request Forgery Vulnerabilities
BID:64993
Info
VMware vCloud Director Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 64993 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1211 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2014 12:00AM |
| Updated: | Apr 08 2014 12:38AM |
| Credit: | Mattia Folador |
| Vulnerable: |
Avaya Aura System Manager 6.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 |
| Not Vulnerable: | |
Discussion
VMware vCloud Director Cross Site Request Forgery Vulnerabilities
VMware vCloud Director is prone to multiple cross-site request-forgery vulnerabilities because it fails to properly validate HTTP requests.
An attacker can exploit these issues to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
vCloud Director 5.5 and 5.1.x are vulnerable.
VMware vCloud Director is prone to multiple cross-site request-forgery vulnerabilities because it fails to properly validate HTTP requests.
An attacker can exploit these issues to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
vCloud Director 5.5 and 5.1.x are vulnerable.
Exploit / POC
VMware vCloud Director Cross Site Request Forgery Vulnerabilities
To exploit these issues an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit these issues an attacker must entice an unsuspecting victim to open a malicious URI.
Solution / Fix
VMware vCloud Director Cross Site Request Forgery Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
VMware vCloud Director Cross Site Request Forgery Vulnerabilities
References:
References:
- VMware Homepage (VMware)