First published: Fri Mar 16 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in VMware vShield Manager (vSM) 1.0.1 before Update 2 and 4.1.0 before Update 2 allows remote attackers to hijack the authentication of arbitrary users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vShield Manager | <=1.0 | |
VMware vShield Manager | <=4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1514 is classified as a medium-severity vulnerability due to its potential to allow unauthorized actions by remote attackers.
To fix CVE-2012-1514, upgrade VMware vShield Manager to version 1.0.1 Update 2 or 4.1.0 Update 2 or later.
CVE-2012-1514 can facilitate cross-site request forgery (CSRF) attacks that may allow attackers to impersonate users.
CVE-2012-1514 affects VMware vShield Manager 1.0.1 before Update 2 and 4.1.0 before Update 2.
Prevent the exploitation of CVE-2012-1514 by ensuring that users are authenticated via secure tokens and by regularly updating your software to the latest versions.