First published: Wed Jun 07 2017(Updated: )
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vSphere Data Protection | =5.5.1 | |
VMware vSphere Data Protection | =5.5.5 | |
VMware vSphere Data Protection | =5.5.6 | |
VMware vSphere Data Protection | =5.5.7 | |
VMware vSphere Data Protection | =5.5.8 | |
VMware vSphere Data Protection | =5.5.9 | |
VMware vSphere Data Protection | =5.5.10 | |
VMware vSphere Data Protection | =5.5.11 | |
VMware vSphere Data Protection | =5.8.0 | |
VMware vSphere Data Protection | =5.8.1 | |
VMware vSphere Data Protection | =5.8.2 | |
VMware vSphere Data Protection | =5.8.3 | |
VMware vSphere Data Protection | =5.8.4 | |
VMware vSphere Data Protection | =6.0.0 | |
VMware vSphere Data Protection | =6.0.1 | |
VMware vSphere Data Protection | =6.0.2 | |
VMware vSphere Data Protection | =6.0.3 | |
VMware vSphere Data Protection | =6.0.4 | |
VMware vSphere Data Protection | =6.1.0 | |
VMware vSphere Data Protection | =6.1.1 | |
VMware vSphere Data Protection | =6.1.2 | |
VMware vSphere Data Protection | =6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4914 is considered to have a high severity due to the potential for remote code execution.
To fix CVE-2017-4914, upgrade VMware vSphere Data Protection to the latest patched version provided by VMware.
CVE-2017-4914 affects VMware vSphere Data Protection versions 5.5.x, 5.8.x, and 6.0.x, including specific sub-versions listed.
Yes, CVE-2017-4914 can be exploited remotely by an attacker due to its deserialization vulnerability.
Exploitation of CVE-2017-4914 could allow an attacker to execute arbitrary commands on the affected VMware vSphere Data Protection appliance.