QID 730528
Date Published: 2022-06-21
QID 730528: VMware HCX Information Disclosure Vulnerability (VMSA-2022-0017)
VMware HCX is an application mobility platform designed for simplifying application migration, workload rebalancing and business continuity across datacenters and clouds.
Affected Versions:
VMware HCX version(s) 4.3.1 and 4.3.2
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable VMware HCX via banner grabbing at the /hybridity/api/endpointInfo
A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information.
Solution
VMware has released patch
Refer to VMware advisory VMSA-2022-0017
Vendor References
- VMSA-2022-0017 -
www.vmware.com/security/advisories/VMSA-2022-0017.html
CVEs related to QID 730528
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0017 |
|