vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root on a vROps machine. Note: the admin user (non-sudoer) should not be confused with root of the vROps machine.
References
Link Resource
http://www.securityfocus.com/bid/106242 Third Party Advisory VDB Entry
https://www.vmware.com/security/advisories/VMSA-2018-0031.html Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: vmware

Published: 2018-12-18T20:00:00

Updated: 2018-12-19T10:57:01

Reserved: 2018-02-14T00:00:00


Link: CVE-2018-6978

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-12-18T20:29:00.213

Modified: 2019-10-03T00:03:26.223


Link: CVE-2018-6978

JSON object: View

cve-icon Redhat Information

No data.

CWE