QID 730722

Date Published: 2023-02-10

QID 730722: VMware vRealize Operations (vROps) Cross-Site Request Forgery (CSRF) Bypass Vulnerability (VMSA-2023-0002)

vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the platform on behalf of the authenticated victim user.

Affected Versions:
VMware vRealize Operations (vROps) 8.6.x prior to build 21139695.

QID Detection logic (Unauthenticated):
This QID sends the GET request to ui/login.action and checks for vulnerable version.

Successful exploitation of the vulnerability may allow a remote attacker to execute actions on the platform on behalf of the authenticated victim user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released patch, customers are advised to upgrade to build 21139695. For more information please refer to VMSA-2023-0002

    CVEs related to QID 730722

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2023-0002 URL Logo www.vmware.com/security/advisories/VMSA-2023-0002.html