CVE-2017-4952

VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may result in information disclosure.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:xenon:1.3.7:cr1_2:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.7_7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr6_1:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr7:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.1.0:cr0-3:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.1.0:cr3_1:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr2:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr3:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr4:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr5:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.4.2:cr4_1:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4_8:*:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr6:*:*:*:*:*:*
cpe:2.3:a:vmware:xenon:1.5.4:cr6_2:*:*:*:*:*:*

Information

Published : 2018-05-02 07:29

Updated : 2019-10-02 17:03


NVD link : CVE-2017-4952

Mitre link : CVE-2017-4952


JSON object : View

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

Advertisement

dedicated server usa

Products Affected

vmware

  • xenon