QID 375539
Date Published: 2021-07-28
QID 375539: VMware Carbon Black Cloud Workload Appliance Incorrect URL Handling Vulnerability (VMSA-2021-0005)
Carbon Black Cloud Workload is a data center security product that protects your workloads running in a virtualized environment.
A URL on the administrative interface of the VMware Carbon Black Cloud Workload appliance can be manipulated to bypass authentication. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.1
Affected Versions:
VMware Carbon Black Cloud Workload appliance 1.0.1 and prior
QID Detection Logic
This QID detects vulnerable version of VMware Carbon Black Cloud Workload appliance on the system
A malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance may be able to obtain a valid authentication token, granting access to the administration API of the appliance. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.
None
- VMSA-2021-0005 -
www.vmware.com/security/advisories/VMSA-2021-0005.html
CVEs related to QID 375539
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2021-0005 |
|