QID 377961
QID 377961: VMware vRealize Operations (vROps) CSRF Bypass Vulnerability (VMSA-2023-0002)
vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the platform on behalf of the authenticated victim user.
Affected Versions:
VMware vRealize Operations (vROps) 8.6.x prior to build 21139695.
QID Detection Logic:(Authenticated)
It reads /opt/vmware/etc/appliance-manifest.xml file to check the vulnerable version of the product.
Successful exploitation of the vulnerability may allow a remote attacker to execute actions on the platform on behalf of the authenticated victim user.
Solution
Vendor has released patch, customers are advised to upgrade to build 21139695. For more information please refer to VMSA-2023-0002
Vendor References
- VMSA-2023-0002 -
www.vmware.com/security/advisories/VMSA-2023-0002.html
CVEs related to QID 377961
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2023-0002 |
|