First published: Thu Dec 29 2016(Updated: )
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Vrealize Operations | =6.0.0 | |
Vmware Vrealize Operations | =6.1.0 | |
Vmware Vrealize Operations | =6.2.0a | |
Vmware Vrealize Operations | =6.2.1 | |
Vmware Vrealize Operations | =6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.