CVE-2017-4930: XSS
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user being redirected to a malicious URL.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4930?
CVE-2017-4930 has a medium severity level that could lead to unauthorized redirection of users to malicious URLs.
How do I fix CVE-2017-4930?
To fix CVE-2017-4930, upgrade VMware AirWatch Console to version 9.2.0 or later.
Who is affected by CVE-2017-4930?
CVE-2017-4930 affects authenticated users of VMware AirWatch Console versions prior to 9.2.0.
What type of vulnerability is CVE-2017-4930?
CVE-2017-4930 is a web application vulnerability that allows the injection of malicious URLs.
What could happen if CVE-2017-4930 is exploited?
If exploited, CVE-2017-4930 could redirect users to malicious URLs, threatening user security and data.