vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.
References
Link | Resource |
---|---|
https://www.vmware.com/security/advisories/VMSA-2020-0003.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: vmware
Published: 2020-02-19T20:04:00
Updated: 2020-02-19T20:04:00
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-3943
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-19T21:15:11.437
Modified: 2021-07-21T11:39:23.747
Link: CVE-2020-3943
JSON object: View
Redhat Information
No data.
CWE