CVE-2016-5335: High severity vmware workspace one access and identity manager vulnerability
Published Aug 31, 2016
·Updated
VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
Affected Software
2 affected components
VMware Identity Manager>=2.0<2.7
VMware vRealize Automation>=7.0<7.1
Remediation
Event History
Aug 31, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5335?
CVE-2016-5335 is considered a critical vulnerability due to its potential to allow local users to gain root access.
2
How do I fix CVE-2016-5335?
To fix CVE-2016-5335, upgrade VMware Identity Manager to version 2.7 or later and vRealize Automation to version 7.1 or later.
3
Who is affected by CVE-2016-5335?
CVE-2016-5335 affects local users on VMware Identity Manager versions prior to 2.7 and vRealize Automation versions prior to 7.1.
4
What are the potential risks associated with CVE-2016-5335?
The risks of CVE-2016-5335 include unauthorized root access, which could lead to full system compromise.
5
When was CVE-2016-5335 discovered?
CVE-2016-5335 was published in June 2016 as part of VMware's security advisory.