First published: Thu Dec 11 2014(Updated: )
AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direct object reference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware AirWatch Inbox | <=7.3.3.0 | |
VMware AirWatch Inbox | =7.3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8372 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive organizational information.
To remediate CVE-2014-8372, upgrade to VMware AirWatch On-Premise version 7.3.3.0 or later.
Exploitation of CVE-2014-8372 could allow remote authenticated users to access organizational data from other tenants, leading to data leakage and privacy breaches.
CVE-2014-8372 affects VMware AirWatch versions prior to 7.3.3.0, including version 7.3.0.0.
CVE-2014-8372 is a remote vulnerability that can be exploited by authenticated users from any location.